{"id":"GHSA-c8m9-mh38-97p9","summary":"XML external entity (XXE) vulnerability","details":"An XML eXternal Entity (XXE) Injection was discovered in pmml-model before version 1.4.3. A remote attacker can exploit this vulnerability by sending a request to submit malicious External Entity references within the embedded XML metadata to the target system. ","modified":"2024-12-01T05:33:37.635185Z","published":"2021-02-24T19:40:41Z","withdrawn":"2021-02-24T19:40:41Z","database_specific":{"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2019-05-29T19:15:07Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/jpmml/jpmml-model/commit/494f821ee55e6b1f2949c78781c1d0fa8517867e#diff-322a783849e2119b37122dd21b0f48f2"},{"type":"WEB","url":"https://www.whitesourcesoftware.com/vulnerability-database/WS-2019-0065"}],"affected":[{"package":{"name":"org.jpmml:pmml-model","ecosystem":"Maven","purl":"pkg:maven/org.jpmml/pmml-model"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.3"}]}],"versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.2","1.0.20","1.0.21","1.0.22","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.1","1.1.10","1.1.11","1.1.12","1.1.13","1.1.14","1.1.15","1.1.16","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8","1.1.9","1.2.0","1.2.1","1.2.10","1.2.11","1.2.12","1.2.13","1.2.14","1.2.15","1.2.16","1.2.17","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.3.8","1.3.9","1.4.0","1.4.1","1.4.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-c8m9-mh38-97p9/GHSA-c8m9-mh38-97p9.json"}}],"schema_version":"1.9.0"}