PT-2017-12605 · Apache · Apache Opennlp

Nishil Shah

·

Published

2017-10-02

·

Updated

2022-05-17

·

CVE-2017-12620

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache OpenNLP versions 1.5.0 through 1.5.3 Apache OpenNLP version 1.6.0 Apache OpenNLP versions 1.7.0 through 1.7.2 Apache OpenNLP versions 1.8.0 through 1.8.1
Description The issue allows for an XXE attack when loading models or dictionaries containing XML, specifically affecting applications that load these resources from untrusted sources.
Recommendations For Apache OpenNLP versions 1.5.0 through 1.5.3, update to a version outside of this range to resolve the issue. For Apache OpenNLP version 1.6.0, update to a version outside of this range to resolve the issue. For Apache OpenNLP versions 1.7.0 through 1.7.2, update to a version outside of this range to resolve the issue. For Apache OpenNLP versions 1.8.0 through 1.8.1, update to a version outside of this range to resolve the issue.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-12620
GHSA-H22X-HM8G-RXPG

Affected Products

Apache Opennlp