Vulnerability GHSA-h22x-hm8g-rxpg
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
4 years ago
May 17, 2022 at 12:29 AM UTC
Improper Restriction of XML External Entity Reference in Apache OpenNLP
1.6.0 and 1.8.0 - 1.8.1
1.6.0 and 1.8.0 - 1.8.1
Summary
Improper Restriction of XML External Entity Reference in Apache OpenNLP
Details
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
5 months ago
Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation
1.6.0 - 2.2.0 and 2.4.0 and 2.5.7 - 3.0.0 GHSA-659w-93r5-9j6m
1.6.0 - 2.2.0 and 2.4.0 and 2.5.7 - 3.0.0 GHSA-659w-93r5-9j6m
Critical
5 months ago
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
1.6.0 - 2.2.0 and 2.4.0 and 2.5.7 - 3.0.0 GHSA-cx4m-2p55-rw7j
1.6.0 - 2.2.0 and 2.4.0 and 2.5.7 - 3.0.0 GHSA-cx4m-2p55-rw7j
Critical
5 months ago
Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing
1.6.0 - 2.2.0 and 2.4.0 and 2.5.7 - 3.0.0 GHSA-4v8g-86x5-3vrc
1.6.0 - 2.2.0 and 2.4.0 and 2.5.7 - 3.0.0 GHSA-4v8g-86x5-3vrc
Impacted packages
Timeline
Published
4 years ago
May 17, 2022 at 12:29 AM UTC
Fixed (1.8.2)
Unknown
Unknown
Last Modified
2 years ago
November 08, 2023 at 03:58 AM UTC