dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Dom4j Project Subscribe
Oncommand Api Services Subscribe
Oncommand Workflow Automation Subscribe
Snap Creator Framework Subscribe
Snapcenter Subscribe
Snapmanager Subscribe
Opensuse Subscribe
Agile Plm Subscribe
Application Testing Suite Subscribe
Banking Platform Subscribe
Business Process Management Suite Subscribe
Communications Application Session Controller Subscribe
Communications Diameter Signaling Router Subscribe
Communications Unified Inventory Management Subscribe
Data Integrator Subscribe
Documaker Subscribe
Endeca Information Discovery Integrator Subscribe
Enterprise Data Quality Subscribe
Enterprise Manager Base Platform Subscribe
Financial Services Analytical Applications Infrastructure Subscribe
Flexcube Core Banking Subscribe
Fusion Middleware Subscribe
Health Sciences Empirica Signal Subscribe
Health Sciences Information Manager Subscribe
Insurance Policy Administration J2ee Subscribe
Insurance Rules Palette Subscribe
Jdeveloper Subscribe
Primavera P6 Enterprise Project Portfolio Management Subscribe
Rapid Planning Subscribe
Retail Customer Management And Segmentation Foundation Subscribe
Retail Integration Bus Subscribe
Retail Order Broker Subscribe
Retail Price Management Subscribe
Retail Xstore Point Of Service Subscribe
Storagetek Tape Analytics Sw Tool Subscribe
Utilities Framework Subscribe
Webcenter Portal Subscribe
Jboss Enterprise Application Platform Subscribe
Jboss Enterprise Application Platform Cd Subscribe
Jboss Enterprise Bpms Platform Subscribe
Jboss Enterprise Brms Platform Subscribe
Jboss Fuse Subscribe
Jboss Single Sign On Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2191-1 dom4j security update
EUVD EUVD EUVD-2020-0492 dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Github GHSA Github GHSA GHSA-hwj3-m3p6-hj38 dom4j allows External Entities by default which might enable XXE attacks
Ubuntu USN Ubuntu USN USN-4575-1 dom4j vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T11:06:11.156Z

Reserved: 2020-03-20T00:00:00

Link: CVE-2020-10683

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-01T19:15:12.927

Modified: 2024-11-21T04:55:50.587

Link: CVE-2020-10683

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-04-15T00:00:00Z

Links: CVE-2020-10683 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses