{"id":"CGA-rx24-xxp5-473v","modified":"2026-09-08T18:27:43.747852181Z","published":"2026-09-07T14:23:25Z","upstream":["CVE-2020-10683","GHSA-hwj3-m3p6-hj38"],"references":[{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html"},{"type":"ADVISORY","url":"https://github.com/dom4j/dom4j/issues/87"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20200518-0002/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4575-1/"},{"type":"ADVISORY","url":"https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html"},{"type":"ADVISORY","url":"https://github.com/dom4j/dom4j/releases/tag/version-2.1.3"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"FIX","url":"https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"FIX","url":"https://github.com/dom4j/dom4j/commits/version-2.0.3"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1694235"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2021.html"}],"affected":[{"package":{"name":"eco-java-gradle-3.4","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/eco-java-gradle-3.4?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"component_purl":"pkg:maven/dom4j@1.6.1","latest_event_status":"pending_upstream_fix","latest_event_timestamp":"2026-09-07T14:23:53Z","component_name":"dom4j","component_version":"1.6.1","component_type":"java-archive","component_location":"/usr/lib/gradle/3.4/lib/dom4j-1.6.1.jar"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-rx24-xxp5-473v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}