PT-2018-9485 · Dom4J+3 · Dom4J+3
Published
2018-07-01
·
Updated
2026-05-19
·
CVE-2018-1000632
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
dom4j versions prior to 2.1.1
Description
The issue is related to an XML Injection vulnerability in the Class: Element, specifically in the
addElement and addAttribute methods. This can result in an attacker tampering with XML documents through XML injection, which appears to be exploitable via an attacker specifying attributes or elements in the XML document.Recommendations
For dom4j versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the
addElement and addAttribute methods in the Element class until a patch is available.
Restrict access to the vulnerable Class: Element to minimize the risk of exploitation.
Avoid using the addElement and addAttribute methods in the affected XML documents until the issue is resolved.Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Os
Suse
Ubuntu
Dom4J