When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4039 | When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected. |
Github GHSA |
GHSA-h22x-hm8g-rxpg | Improper Restriction of XML External Entity Reference in Apache OpenNLP |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://opennlp.apache.org/news/cve-2017-12620.html |
|
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T19:15:51.072Z
Reserved: 2017-08-07T00:00:00
Link: CVE-2017-12620
No data.
Status : Deferred
Published: 2017-10-03T01:29:01.233
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-12620
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA