PT-2019-4677 · Apache+1 · Apache Poi+1

Publicado

2019-10-20

·

Atualizado

2022-05-24

·

CVE-2019-12415

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache POI versions up to 4.1.0
Description The issue is related to the XSSFExportToXml tool in Apache POI, which can be exploited to read files from the local filesystem or internal network resources via XML External Entity (XXE) Processing when converting user-provided Microsoft Excel documents. This is due to insufficient restrictions on XML external entities.
Recommendations For Apache POI versions up to 4.1.0, consider disabling the XSSFExportToXml tool until a patch is available to prevent potential exploitation. Restrict access to sensitive files and network resources to minimize the risk of unauthorized access.

Exploit

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00970
CVE-2019-12415
GHSA-9JWC-Q6J3-8G9G

Produtos afetados

Apache Poi
Debian