PT-2022-26190 · Dragonfly · Dragonfly

Joshuasing

·

Published

2022-12-27

·

Updated

2023-01-06

·

CVE-2022-41967

CVSS v3.1

7.0

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Dragonfly version 0.3.0-SNAPSHOT
Description The issue concerns a Java runtime dependency management library that does not configure DocumentBuilderFactory to prevent XML external entity (XXE) attacks. This can be avoided by not trying to resolve SNAPSHOT versions, as the library only parses XML for such versions.
Recommendations For Dragonfly version 0.3.0-SNAPSHOT, update to version 0.3.1-SNAPSHOT to resolve the issue. As a temporary workaround, consider avoiding the resolution of SNAPSHOT versions to minimize the risk of exploitation.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2022-41967
GHSA-6X3M-96QP-MMXV

Affected Products

Dragonfly