Description
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4039 | When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected. |
Github GHSA |
GHSA-h22x-hm8g-rxpg | Improper Restriction of XML External Entity Reference in Apache OpenNLP |
References
| Link | Providers |
|---|---|
| http://opennlp.apache.org/news/cve-2017-12620.html |
|
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T19:15:51.072Z
Reserved: 2017-08-07T00:00:00.000Z
Link: CVE-2017-12620
No data.
Status : Deferred
Published: 2017-10-03T01:29:01.233
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-12620
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA