PT-2018-5970 · Apache · Apache Uima+3

Joern Kottmann

·

Publicado

2018-04-26

·

Atualizado

2022-05-14

·

CVE-2017-15691

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache uimaj versions prior to 2.10.2 Apache uimaj 3.0.0-xxx versions prior to 3.0.0-beta Apache uima-as versions prior to 2.10.2 Apache uimaFIT versions prior to 2.4.0 Apache uimaDUCC versions prior to 2.2.2
Description: The issue relates to an XML external entity expansion (XXE) capability of various XML parsers. UIMA, as part of its configuration and operation, may read XML from various sources, which could be tainted in ways to cause inadvertent disclosure of local files or other internal content.
Recommendations: For Apache uimaj versions prior to 2.10.2, update to version 2.10.2 or later. For Apache uimaj 3.0.0-xxx versions prior to 3.0.0-beta, update to version 3.0.0-beta or later. For Apache uima-as versions prior to 2.10.2, update to version 2.10.2 or later. For Apache uimaFIT versions prior to 2.4.0, update to version 2.4.0 or later. For Apache uimaDUCC versions prior to 2.2.2, update to version 2.2.2 or later.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15691
GHSA-WP2F-HRG2-3R5M

Produtos afetados

Apache Uima-As
Apache Uima Ducc
Apache Uimafit
Apache Uima