Vulnerability that affects org.apache.pdfbox:pdfbox
Critical severity
GitHub Reviewed
Published
Jul 5, 2019
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Package
Affected versions
>= 2.0.14, < 2.0.15
Patched versions
2.0.15
Description
Published by the National Vulnerability Database
Apr 17, 2019
Published to the GitHub Advisory Database
Jul 5, 2019
Reviewed
Jun 16, 2020
Last updated
Feb 1, 2023
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
References