{"id":"GHSA-9jwc-q6j3-8g9g","summary":"Improper Restriction of XML External Entity Reference in Apache POI ","details":"In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.","aliases":["CVE-2019-12415"],"modified":"2023-11-08T04:01:04.785042Z","published":"2022-05-24T16:59:46Z","database_specific":{"github_reviewed_at":"2022-06-28T14:11:47Z","nvd_published_at":"2019-10-23T20:15:00Z","cwe_ids":["CWE-611"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-12415"},{"type":"PACKAGE","url":"https://github.com/apache/poi"},{"type":"WEB","url":"https://lists.apache.org/thread.html/13a54b6a03369cfb418a699180ffb83bd727320b6ddfec198b9b728e@%3Cannounce.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/2ac0327748de0c2b3c1c012481b79936797c711724e0b7da83cf564c@%3Cuser.tika.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/895164e03a3c327449069e2fd6ced0367561878b3ae6a8ec740c2007@%3Cuser.tika.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/d88b8823867033514d7ec05d66f88c70dc207604d3dcbd44fd88464c@%3Cuser.tika.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E"},{"type":"WEB","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"}],"affected":[{"package":{"name":"org.apache.poi:poi","ecosystem":"Maven","purl":"pkg:maven/org.apache.poi/poi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1"}]}],"versions":["3.0-FINAL","3.0.1-FINAL","3.0.2-FINAL","3.0.2-beta1","3.0.2-beta2","3.1-FINAL","3.1-beta1","3.1-beta2","3.10-FINAL","3.10-beta1","3.10-beta2","3.10.1","3.11","3.11-beta1","3.11-beta2","3.11-beta3","3.12","3.12-beta1","3.13","3.13-beta1","3.14","3.14-beta1","3.15","3.15-beta1","3.15-beta2","3.16","3.16-beta1","3.16-beta2","3.17","3.17-beta1","3.2-FINAL","3.5-FINAL","3.5-beta1","3.5-beta3","3.5-beta4","3.5-beta5","3.5-beta6","3.6","3.7","3.7-beta1","3.7-beta2","3.7-beta3","3.8","3.8-beta1","3.8-beta2","3.8-beta3","3.8-beta4","3.8-beta5","3.9","4.0.0","4.0.1","4.1.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 4.1.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9jwc-q6j3-8g9g/GHSA-9jwc-q6j3-8g9g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}