CVE-2017-9096

Updated on 08 Nov 2017

Severity

8.8 High severity

Details

CVSS score
8.8
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Overview

About vulnerability

The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.

Details

Affected product:
cocoon , itextpdf
Affected packages:
cocoon-batik-sample @ 2.3.0 (+232 more)
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.

Fixes