Description
Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/github/bonigarcia/wdm/WebDriverManager.java.

This issue affects webdrivermanager: from 1.0.0 before 6.0.2.
Published: 2025-05-14
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14900 Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/github/bonigarcia/wdm/WebDriverManager.java. This issue affects webdrivermanager: from 1.0.0 before 6.0.2.
Github GHSA Github GHSA GHSA-pwm3-776c-8q7q BoniGarcia WebDriverManager Affected By Improper Restriction of XML External Entity Reference
History

Wed, 14 May 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 May 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/github/bonigarcia/wdm/WebDriverManager.java. This issue affects webdrivermanager: from 1.0.0 before 6.0.2.
Title XML External Entity (XXE) injection vulnerability in WebDriverManager
Weaknesses CWE-611
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GovTech CSG

Published:

Updated: 2025-05-14T20:49:57.890Z

Reserved: 2025-05-13T02:36:29.519Z

Link: CVE-2025-4641

cve-icon Vulnrichment

Updated: 2025-05-14T20:49:55.420Z

cve-icon NVD

Status : Deferred

Published: 2025-05-14T19:15:53.683

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-4641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses