QID 981599
QID 981599: Java (maven) Security Update for com.puppycrawl.tools:checkstyle (GHSA-763g-fqq7-48wg)
Due to an incomplete fix for [CVE-2019-9658](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9658), checkstyle was still vulnerable to XML External Entity (XXE) Processing.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
_Has the problem been patched? What versions should users upgrade to?_
Patched, will be released with version 8.29 at 26 Jan 2020.Workaround:
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
No workaround are available
Patched, will be released with version 8.29 at 26 Jan 2020.Workaround:
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
No workaround are available
Vendor References
- GHSA-763g-fqq7-48wg -
github.com/advisories/GHSA-763g-fqq7-48wg
CVEs related to QID 981599
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-763g-fqq7-48wg | com.puppycrawl.tools:checkstyle |
|