A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-14338.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.12.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.12.0-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.12.0-sp2"
}
]
}
]