QID 981705

QID 981705: Java (maven) Security Update for ro.pippo:pippo-jaxb (GHSA-hwcx-9p4j-7hwj)

XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts of heap memory is taken. Eventually, the JVM process will run out of memory. Otherwise, if the OS does not bound the memory on that process, memory will continue to be exhausted and will affect other processes on the system.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-hwcx-9p4j-7hwj for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981705

    Software Advisories
    Advisory ID Software Component Link
    GHSA-hwcx-9p4j-7hwj ro.pippo:pippo-jaxb URL Logo github.com/advisories/GHSA-hwcx-9p4j-7hwj