Improper Restriction of XML External Entity Reference in iText
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Mar 6, 2024
Description
Published by the National Vulnerability Database
Nov 8, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jun 30, 2022
Last updated
Mar 6, 2024
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.
References