IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.
References
Link | Resource |
---|---|
https://youtrack.jetbrains.com/issue/IDEA-175381 | Broken Link |
https://research.checkpoint.com/parsedroid-targeting-android-development-research-community/ | Exploit Third Party Advisory |
http://git.jetbrains.org/?p=idea/adt-tools-base.git;a=commit;h=a778b2b88515513654e002cd51cbe8eb8226e96b | Patch Third Party Advisory |
Configurations
Information
Published : 2018-08-03 08:29
Updated : 2018-10-23 04:25
NVD link : CVE-2017-8316
Mitre link : CVE-2017-8316
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
jetbrains
- intellij_idea