{"id":"CVE-2017-18197","details":"In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.","aliases":["GHSA-wvpv-8524-wg6x"],"modified":"2026-07-08T11:49:33.284596Z","published":"2018-02-24T02:29:01.893Z","related":["openSUSE-SU-2024:10879-1"],"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/03/msg00002.html"},{"type":"EVIDENCE","url":"https://github.com/jgraph/mxgraph/issues/124"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jgraph/mxgraph","events":[{"introduced":"0"},{"last_affected":"8dea670d0aba25347900869c023bb1710832371d"}],"database_specific":{"cpe":"cpe:2.3:a:jgraph:mxgraph:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.7.5"}],"source":"CPE_RANGE"}}],"versions":["v3.7.5","v3.7.4","v3.7.3","v3.7.2","v3.7.1","v3.7.0.1","v3.7.0.0","v3.6.0.0","v3.5.1.5","v3.5.1.4","v3.5.1.3","v3.5.1.2","v3.5.1.1","v3.5.1.0","v3.5.0.0","v3.4.1.3","v3.4.1.2","v3.4.1.1","v3.4.1.0","v3.4.0.3","v3.4.0.2","v3.4.0.1","v3.4.0.0","v3.3.1.1","v3.3.1.0","v3.3.0.1","v3.3.0.0","v3.2.0.0","v3.1.3.0","v3.1.2.2","v3.1.2.1","v3.1.2.0","v3.1.1.1","v3.1.1.0","v3.1.0.1","v3.1.0.0","v3.0.1.1","v3.0.1.0","v3.0.0.0","v2.9.0.1","v2.9.0.0","v2.8.2.0","v2.8.1.0","v2.8.0.0","v2.7.0.0","v2.6.0.0","v2.5.1.0","v2.5.0.3","v2.5.0.2","v2.5.0.1","v2.5.0.0","v2.4.1.0","v2.4.0.4","v2.4.0.3","v2.4.0.2","v2.4.0.1","v2.4.0.0","v2.3.0.5","v2.3.0.4","v2.3.0.3","v2.3.0.2","v2.3.0.1","v2.3.0.0","v2.2.0.5","v2.2.0.4","v2.2.0.3","v2.2.0.2","v2.2.0.1","v2.2.0.0","v2.1.1.2","v2.1.1.1","v2.1.1.0","v2.1.0.9","v2.1.0.8","v2.1.0.7","v2.1.0.6","v2.1.0.5","v2.1.0.4","v2.1.0.3","v2.1.0.2","v2.1.0.1","v2.1.0.0","v2.0.0.1","v1.13.0.0","v1.12.0.2","v1.12.0.1","v1.12.0.0","v1.11.0.0","v1.10.4.3","v1.10.4.2","v1.10.4.1","v1.10.4.0","v1.10.3.2","vpages-test-1700-24092012","vdeployment_test","v1.10.3.1","1.10.3.0","v1.10.2.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-18197.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}