It was found that the CoreParser class in Lucene accepts doctype declaration and expands external entities. An attacker could use this flaw to bypass security restrictions and access sensitive data (CVE-2017-12629).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0403.json"