A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:redhat:xerces:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"fixed": "2.12.0"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:a:redhat:xerces:2.12.0:sp1:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "2.12.0-sp1"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:a:redhat:xerces:2.12.0:sp2:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "2.12.0-sp2"
}
],
"source": "CPE_FIELD"
}
]
}