MGASA-2019-0077

Source
https://advisories.mageia.org/MGASA-2019-0077.html
Import Source
https://advisories.mageia.org/MGASA-2019-0077.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2019-0077
Related
Published
2019-02-14T08:38:16Z
Modified
2019-02-14T08:07:12Z
Summary
Updated dom4j packages fix security vulnerability
Details

dom4j version prior to version 2.1.1 contains an XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appears to be exploitable via an attacker specifying attributes or elements in the XML document (CVE-2018-1000632).

References
Credits

Affected packages

Mageia:6 / dom4j

Package

Name
dom4j
Purl
pkg:rpm/mageia/dom4j?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.1-28.1.mga6

Ecosystem specific

{
    "section": "core"
}