{"id":"GHSA-hwj3-m3p6-hj38","summary":"dom4j allows External Entities by default which might enable XXE attacks","details":"dom4j before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.\n\nNote: This advisory applies to `dom4j:dom4j` version 1.x legacy artifacts.  To resolve this a change to the latest version of `org.dom4j:dom4j` is recommended.","aliases":["CVE-2020-10683"],"modified":"2024-03-08T05:17:29.315551Z","published":"2020-06-05T16:13:36Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-06-04T19:38:22Z","nvd_published_at":"2020-05-01T19:15:00Z","cwe_ids":["CWE-611"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10683"},{"type":"WEB","url":"https://github.com/dom4j/dom4j/issues/87"},{"type":"WEB","url":"https://github.com/dom4j/dom4j/commit/1707bf3d898a8ada3b213acb0e3b38f16eaae73d"},{"type":"WEB","url":"https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"WEB","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"WEB","url":"https://usn.ubuntu.com/4575-1"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20200518-0002"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51@%3Cnotifications.freemarker.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32@%3Cdev.velocity.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8@%3Cdev.velocity.apache.org%3E"},{"type":"WEB","url":"https://github.com/dom4j/dom4j/releases/tag/version-2.1.3"},{"type":"WEB","url":"https://github.com/dom4j/dom4j/commits/version-2.0.3"},{"type":"PACKAGE","url":"https://github.com/dom4j/dom4j"},{"type":"WEB","url":"https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1694235"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html"}],"affected":[{"package":{"name":"org.dom4j:dom4j","ecosystem":"Maven","purl":"pkg:maven/org.dom4j/dom4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.3"}]}],"versions":["2.0.0","2.0.0-RC1","2.0.1","2.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-hwj3-m3p6-hj38/GHSA-hwj3-m3p6-hj38.json"}},{"package":{"name":"org.dom4j:dom4j","ecosystem":"Maven","purl":"pkg:maven/org.dom4j/dom4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.3"}]}],"versions":["2.1.0","2.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-hwj3-m3p6-hj38/GHSA-hwj3-m3p6-hj38.json"}},{"package":{"name":"dom4j:dom4j","ecosystem":"Maven","purl":"pkg:maven/dom4j/dom4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.6.1"}]}],"versions":["1.1","1.3","1.4","1.4-dev-2","1.4-dev-3","1.4-dev-4","1.4-dev-5","1.4-dev-6","1.4-dev-7","1.4-dev-8","1.5","1.5-beta-2","1.5-rc1","1.5.1","1.5.2","1.6","1.6.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-hwj3-m3p6-hj38/GHSA-hwj3-m3p6-hj38.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}