jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
References
Link | Resource |
---|---|
https://github.com/pippo-java/pippo/issues/486 | Issue Tracking Exploit Third Party Advisory |
Configurations
Information
Published : 2018-12-11 02:29
Updated : 2019-01-03 08:15
NVD link : CVE-2018-20059
Mitre link : CVE-2018-20059
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
pippo
- pippo