QID 980671
QID 980671: Java (maven) Security Update for org.apache.any23:apache-any23 (GHSA-838r-hvwh-24h8)
An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-838r-hvwh-24h8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-838r-hvwh-24h8 -
github.com/advisories/GHSA-838r-hvwh-24h8
CVEs related to QID 980671
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-838r-hvwh-24h8 | org.apache.any23:apache-any23 |
|