{"id":"GHSA-fcrx-8829-jpqx","summary":"Improper Restriction of XML External Entity Reference in wutka jox","details":"An XML External Entity (XXE) vulnerability exists in wutka jox 1.16 in the readObject method in JOXSAXBeanInput.","aliases":["CVE-2021-43142"],"modified":"2024-12-05T05:32:51.578094Z","published":"2022-04-01T00:00:45Z","database_specific":{"nvd_published_at":"2022-03-30T22:15:00Z","cwe_ids":["CWE-611"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-04-01T19:59:52Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43142"},{"type":"WEB","url":"https://novysodope.github.io/2021/10/29/64"}],"affected":[{"package":{"name":"com.wutka:jox","ecosystem":"Maven","purl":"pkg:maven/com.wutka/jox"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.16"}]}],"versions":["1.16"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-fcrx-8829-jpqx/GHSA-fcrx-8829-jpqx.json"}}],"schema_version":"1.9.0"}