All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2099-1 | checkstyle security update |
EUVD |
EUVD-2020-0251 | All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658. |
Github GHSA |
GHSA-763g-fqq7-48wg | XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled)) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-04T22:32:01.605Z
Reserved: 2019-04-03T00:00:00
Link: CVE-2019-10782
No data.
Status : Modified
Published: 2020-01-30T23:15:10.093
Modified: 2024-11-21T04:19:54.657
Link: CVE-2019-10782
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA