QID 980962
QID 980962: Java (maven) Security Update for org.apache.juddi:juddi-client (GHSA-p99p-726h-c8v5)
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD type of attacks. Mitigation is to use 3.3.5.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-p99p-726h-c8v5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-p99p-726h-c8v5 -
github.com/advisories/GHSA-p99p-726h-c8v5
CVEs related to QID 980962
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p99p-726h-c8v5 | org.apache.juddi:juddi-client |
|