Skip to content

Poiji XXE prevent attack #264

Answered by ozlerhakan
ruipbferreira asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @ruipbferreira ,

Digging into XXE attacks a bit, I have found that the current Poiji is not affected by this as we use XMLBeans whose version is greater than 4.0.0 according :

13 January 2021 - CVE-2021-23926 - XML External Entity (XXE) Processing in Apache XMLBeans versions prior to 3.0.0
Description:
When parsing XML files using XMLBeans 2.6.0 or below, the underlying parser created by XMLBeans could be susceptible to XML
External Entity (XXE) attacks.
This issue was fixed a few years ago but on review, we decided we should have a CVE to raise awareness of the issue.
Mitigation:
Affected users are advised to update to Apache XMLBeans 3.0.0 or above which fixes this vulnerability. XM…

Replies: 1 comment 25 replies

Comment options

You must be logged in to vote
25 replies
@ruipbferreira
Comment options

@ozlerhakan
Comment options

@ruipbferreira
Comment options

@ruipbferreira
Comment options

@ozlerhakan
Comment options

Answer selected by ruipbferreira
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants