Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Oracle
Subscribe
|
Banking Corporate Lending Process Management
Subscribe
Banking Credit Facilities Process Management
Subscribe
Banking Supply Chain Finance
Subscribe
Banking Trade Finance Process Management
Subscribe
Banking Virtual Account Management
Subscribe
Communications Messaging Server
Subscribe
Communications Session Report Manager
Subscribe
Hyperion Financial Reporting
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Retail Xstore Point Of Service
Subscribe
Webcenter Sites
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0587 | Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF. |
Github GHSA |
GHSA-c9jj-3wvg-q65h | Vulnerability that affects org.apache.pdfbox:pdfbox |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T17:44:15.952Z
Reserved: 2018-11-14T00:00:00.000Z
Link: CVE-2019-0228
No data.
Status : Modified
Published: 2019-04-17T15:29:00.703
Modified: 2024-11-21T04:16:32.607
Link: CVE-2019-0228
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA