Description
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4039 | When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected. |
Github GHSA |
GHSA-h22x-hm8g-rxpg | Improper Restriction of XML External Entity Reference in Apache OpenNLP |
References
| Link | Providers |
|---|---|
| http://opennlp.apache.org/news/cve-2017-12620.html |
|
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T19:15:51.072Z
Reserved: 2017-08-07T00:00:00.000Z
Link: CVE-2017-12620
No data.
Status : Modified
Published: 2017-10-03T01:29:01.233
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-12620
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA