Description
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1299-1 | libjgraphx-java security update |
EUVD |
EUVD-2022-5647 | In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView. |
Github GHSA |
GHSA-wvpv-8524-wg6x | mxGraph vulnerable to XXE attacks |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:13:49.091Z
Reserved: 2018-02-23T00:00:00.000Z
Link: CVE-2017-18197
No data.
Status : Modified
Published: 2018-02-24T02:29:01.893
Modified: 2024-11-21T03:19:32.410
Link: CVE-2017-18197
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA