{"id":"GHSA-fgq9-fc3q-vqmw","summary":"Withdrawn Advisory: dom4j XML Entity Expansion vulnerability","details":"## Withdrawn Advisory\nThis advisory has been withdrawn because [the underlying vulnerability could not be reproduced](https://github.com/joker-xiaoyan/XXE-SAXReader/issues/1#issuecomment-1783780581). This link is maintained to preserve external references.\n\n## Original Description\nAn issue in dom4.j org.dom4.io.SAXReader v.2.1.4 and before allows a remote attacker to obtain sensitive information via the setFeature function.","aliases":["CVE-2023-45960"],"modified":"2026-09-10T03:50:03.680739959Z","published":"2023-10-25T18:32:23Z","withdrawn":"2023-10-31T20:21:23Z","database_specific":{"cwe_ids":["CWE-776"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-10-27T19:50:41Z","nvd_published_at":"2023-10-25T18:17:35Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45960"},{"type":"WEB","url":"https://github.com/dom4j/dom4j/issues/171#issuecomment-1781547256"},{"type":"WEB","url":"https://github.com/joker-xiaoyan/XXE-SAXReader/issues/1"},{"type":"WEB","url":"https://dom4j.github.io"},{"type":"PACKAGE","url":"https://github.com/dom4j/dom4j"},{"type":"WEB","url":"https://github.com/joker-xiaoyan/XXE-SAXReader/blob/8c0d24f9800c36c8ad36457c1df1e4aaff24c7b9/POC.java"},{"type":"WEB","url":"https://github.com/joker-xiaoyan/XXE-SAXReader/tree/main"}],"affected":[{"package":{"name":"org.dom4j:dom4j","ecosystem":"Maven","purl":"pkg:maven/org.dom4j/dom4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.1.4"}]}],"versions":["2.0.0","2.0.0-RC1","2.0.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.3","2.1.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-fgq9-fc3q-vqmw/GHSA-fgq9-fc3q-vqmw.json"}}],"schema_version":"1.9.0"}