When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
References
| Link | Resource |
|---|---|
| http://opennlp.apache.org/news/cve-2017-12620.html | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-10-02 18:29
Updated : 2017-11-02 09:39
NVD link : CVE-2017-12620
Mitre link : CVE-2017-12620
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
apache
- opennlp


