QID 980240
QID 980240: Java (maven) Security Update for org.jdom:jdom (GHSA-2363-cqg2-863c)
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. At this time there is not released fixed version of JDOM. As a workaround, to avoid external entities being expanded, one can call `builder.setExpandEntities(false)` and they won't be expanded.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2363-cqg2-863c for updates pertaining to this vulnerability.
Vendor References
- GHSA-2363-cqg2-863c -
github.com/advisories/GHSA-2363-cqg2-863c
CVEs related to QID 980240
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2363-cqg2-863c | org.jdom:jdom |
|