Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/github/bonigarcia/wdm/WebDriverManager.java.
This issue affects webdrivermanager: from 1.0.0 before 6.0.2.
This issue affects webdrivermanager: from 1.0.0 before 6.0.2.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14900 | Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/github/bonigarcia/wdm/WebDriverManager.java. This issue affects webdrivermanager: from 1.0.0 before 6.0.2. |
Github GHSA |
GHSA-pwm3-776c-8q7q | BoniGarcia WebDriverManager Affected By Improper Restriction of XML External Entity Reference |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/bonigarcia/webdrivermanager/pull/1458 |
|
History
Wed, 14 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 May 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/github/bonigarcia/wdm/WebDriverManager.java. This issue affects webdrivermanager: from 1.0.0 before 6.0.2. | |
| Title | XML External Entity (XXE) injection vulnerability in WebDriverManager | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GovTech CSG
Published:
Updated: 2025-05-14T20:49:57.890Z
Reserved: 2025-05-13T02:36:29.519Z
Link: CVE-2025-4641
Updated: 2025-05-14T20:49:55.420Z
Status : Awaiting Analysis
Published: 2025-05-14T19:15:53.683
Modified: 2025-05-16T14:43:26.160
Link: CVE-2025-4641
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA