[MAVEN:GHSA-G556-X5VX-QH59] Android SVG vulnerable to XML External Entity (XXE)

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution

Package Affected Version
pkg:maven/com.caverock/androidsvg < 1.3
Package Fixed Version
pkg:maven/com.caverock/androidsvg = 1.3
ID
MAVEN:GHSA-G556-X5VX-QH59
Severity
high
URL
https://github.com/advisories/GHSA-g556-x5vx-qh59
Published
2018-10-19T16:50:33
(6 years ago)
Modified
2023-01-09T05:03:31
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.caverock/androidsvg com.caverock androidsvg < 1.3
Fixed pkg:maven/com.caverock/androidsvg com.caverock androidsvg = 1.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...