The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2019-12-04T16:54:22

Updated: 2024-08-05T01:40:15.799Z

Reserved: 2019-10-14T00:00:00

Link: CVE-2019-17554

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-04T17:16:43.867

Modified: 2023-11-07T03:06:19.423

Link: CVE-2019-17554

cve-icon Redhat

No data.