QID 981597
QID 981597: Java (maven) Security Update for org.apache.olingo:odata-server-core (GHSA-mgh8-hcwj-h57v)
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mgh8-hcwj-h57v for updates pertaining to this vulnerability.
Vendor References
- GHSA-mgh8-hcwj-h57v -
github.com/advisories/GHSA-mgh8-hcwj-h57v
CVEs related to QID 981597
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mgh8-hcwj-h57v | org.apache.olingo:odata-client-core |
|
|
| GHSA-mgh8-hcwj-h57v | org.apache.olingo:odata-server-core |
|