{"id":"GHSA-99wh-973f-779p","summary":"XML External Entity Reference in Hazelcast","details":"The AbstractXmlConfigRootTagRecognizer() function makes use of SAXParser generated from a SAXParserFactory with no FEATURE_SECURE_PROCESSING set, allowing for XXE attacks.","aliases":["CVE-2022-0265"],"modified":"2024-02-19T05:33:14.906646Z","published":"2022-03-04T00:00:15Z","database_specific":{"github_reviewed_at":"2022-03-04T19:44:17Z","nvd_published_at":"2022-03-03T22:15:00Z","cwe_ids":["CWE-611"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0265"},{"type":"WEB","url":"https://github.com/hazelcast/hazelcast/pull/20407"},{"type":"WEB","url":"https://github.com/hazelcast/hazelcast/commit/4d6b666cd0291abd618c3b95cdbb51aa4208e748"},{"type":"WEB","url":"https://github.com/hazelcast/hazelcast"},{"type":"WEB","url":"https://huntr.dev/bounties/d63972a2-b910-480a-a86b-d1f75d24d563"}],"affected":[{"package":{"name":"com.hazelcast:hazelcast","ecosystem":"Maven","purl":"pkg:maven/com.hazelcast/hazelcast"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.1-beta1"},{"fixed":"5.1"}]}],"versions":["5.1-BETA-1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-99wh-973f-779p/GHSA-99wh-973f-779p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}