aXMLRPC XML External Entity vulnerability
Critical severity
GitHub Reviewed
Published
Jan 5, 2023
to the GitHub Advisory Database
•
Updated Feb 13, 2024
Description
Published by the National Vulnerability Database
Jan 5, 2023
Published to the GitHub Advisory Database
Jan 5, 2023
Reviewed
Jan 11, 2023
Last updated
Feb 13, 2024
A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0. This vulnerability affects the function
ResponseParser
of the filesrc/main/java/de/timroes/axmlrpc/ResponseParser.java
. The manipulation leads to xml external entity reference. Upgrading to version 1.12.1 is able to address this issue. The name of the patch is ad6615b3ec41353e614f6ea5fdd5b046442a832b. It is recommended to upgrade the affected component. VDB-217450 is the identifier assigned to this vulnerability.References