PT-2019-5542 · Org.Dom4J+2 · Dom4J+2

Published

2019-03-29

·

Updated

2026-05-19

·

CVE-2020-10683

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions dom4j versions 1.x and 2.0.x through 2.1.2 dom4j version 2.1.x before 2.1.3
Description The issue is related to the incorrect restriction of XML links to external objects in the dom4j library, which might enable XXE attacks. This could allow a remote attacker to gain unauthorized access to protected information. The library allows external DTDs and External Entities by default. However, there is external documentation from OWASP that shows how to enable safe, non-default behavior in any application that uses dom4j.
Recommendations For dom4j versions 1.x, change to the latest version of org.dom4j:dom4j. For dom4j versions 2.0.x through 2.1.2, update to version 2.1.3 or later. As a temporary workaround, consider disabling the use of external DTDs and External Entities in dom4j until a patch is available. Restrict access to the new org.dom4j.io.SAXReader() function to minimize the risk of exploitation.

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2020-04038
CVE-2020-10683
DLA-2191-1
GHSA-HWJ3-M3P6-HJ38
MGASA-2021-0034
OPENSUSE-SU-2020:0719-1
OPENSUSE-SU-2020_0719-1
OPENSUSE-SU-2024:10724-1
RHSA-2020:3461
RHSA-2020:3462
RHSA-2020:3463
RHSA-2020:3637
RHSA-2020:3638
RHSA-2020:3639
ROSA-SA-2024-2454
SUSE-SU-2020:1382-1
SUSE-SU-2020:1383-1
USN-4575-1

Affected Products

Suse
Ubuntu
Dom4J