{"api_version":"1","generated_at":"2026-07-24T17:17:22+00:00","cve":"CVE-2019-9843","urls":{"html":"https://cve.report/CVE-2019-9843","api":"https://cve.report/api/cve/CVE-2019-9843.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-9843","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-9843"},"summary":{"title":"CVE-2019-9843","description":"In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-06-28 18:15:00","updated_at":"2023-11-07 03:13:00"},"problem_types":["CWE-611"],"metrics":[],"references":[{"url":"https://github.com/diffplug/spotless/issues/358","name":"https://github.com/diffplug/spotless/issues/358","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"CVE-2019-9843: The XML parser isn't respecting resolveExternalEntities as false · Issue #358 · diffplug/spotless · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/diffplug/spotless/blob/master/plugin-gradle/CHANGES.md#version-3200---march-11th-2018-javadoc-jcenter","name":"https://github.com/diffplug/spotless/blob/master/plugin-gradle/CHANGES.md#version-3200---march-11th-2018-javadoc-jcenter","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"spotless/CHANGES.md at master · diffplug/spotless · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://lists.apache.org/thread.html/r7406e297228c42deeecdd12a576e39d63073faebf14b027b7608fdfd@%3Cissues.iceberg.apache.org%3E","name":"[iceberg-issues] 20210701 [GitHub] [iceberg] jackye1995 opened a new pull request #2776: Build: bump up DiffPlug Spotless version","refsource":"MLIST","tags":[],"title":"Pony Mail!","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/diffplug/spotless/blob/master/plugin-maven/CHANGES.md#version-1200---march-14th-2018-javadoc-jcenter","name":"https://github.com/diffplug/spotless/blob/master/plugin-maven/CHANGES.md#version-1200---march-14th-2018-javadoc-jcenter","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"spotless/CHANGES.md at master · diffplug/spotless · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.apache.org/thread.html/r7406e297228c42deeecdd12a576e39d63073faebf14b027b7608fdfd%40%3Cissues.iceberg.apache.org%3E","name":"[iceberg-issues] 20210701 [GitHub] [iceberg] jackye1995 opened a new pull request #2776: Build: bump up DiffPlug Spotless version","refsource":"","tags":[],"title":"Pony Mail!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/diffplug/spotless/pull/369","name":"https://github.com/diffplug/spotless/pull/369","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"WTP - Ignore external URIs by default by fvgh · Pull Request #369 · diffplug/spotless · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-9843","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9843","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"9843","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"diffplug","cpe5":"gradle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"spotless","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"9843","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"diffplug","cpe5":"gradle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"spotless","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"9843","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"diffplug","cpe5":"maven","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"spotless","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"9843","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"diffplug","cpe5":"maven","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"spotless","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-9843","qid":"982016","title":"Java (maven) Security Update for com.diffplug.spotless:spotless-plugin-maven (GHSA-7v35-qwwj-p98g)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-9843","ASSIGNER":"cve@mitre.org","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://github.com/diffplug/spotless/blob/master/plugin-maven/CHANGES.md#version-1200---march-14th-2018-javadoc-jcenter","url":"https://github.com/diffplug/spotless/blob/master/plugin-maven/CHANGES.md#version-1200---march-14th-2018-javadoc-jcenter"},{"refsource":"MISC","name":"https://github.com/diffplug/spotless/issues/358","url":"https://github.com/diffplug/spotless/issues/358"},{"refsource":"MISC","name":"https://github.com/diffplug/spotless/blob/master/plugin-gradle/CHANGES.md#version-3200---march-11th-2018-javadoc-jcenter","url":"https://github.com/diffplug/spotless/blob/master/plugin-gradle/CHANGES.md#version-3200---march-11th-2018-javadoc-jcenter"},{"refsource":"MISC","name":"https://github.com/diffplug/spotless/pull/369","url":"https://github.com/diffplug/spotless/pull/369"},{"refsource":"MLIST","name":"[iceberg-issues] 20210701 [GitHub] [iceberg] jackye1995 opened a new pull request #2776: Build: bump up DiffPlug Spotless version","url":"https://lists.apache.org/thread.html/r7406e297228c42deeecdd12a576e39d63073faebf14b027b7608fdfd@%3Cissues.iceberg.apache.org%3E"}]},"description":{"description_data":[{"lang":"eng","value":"In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file."}]}},"nvd":{"publishedDate":"2019-06-28 18:15:00","lastModifiedDate":"2023-11-07 03:13:00","problem_types":["CWE-611"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.1},"severity":"MEDIUM","exploitabilityScore":4.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:diffplug:gradle:*:*:*:*:*:spotless:*:*","versionEndExcluding":"3.20.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:diffplug:maven:*:*:*:*:*:spotless:*:*","versionEndExcluding":"1.20.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"9843","Ordinal":"147729","Title":"CVE-2019-9843","CVE":"CVE-2019-9843","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"9843","Ordinal":"1","NoteData":"In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"9843","Ordinal":"2","NoteData":"2019-03-15","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"9843","Ordinal":"3","NoteData":"2021-07-01","Type":"Other","Title":"Modified"}]}}}