[MAVEN:GHSA-HWCX-9P4J-7HWJ] XML Entity Expansion in Pippo

Severity High
Affected Packages 1
CVEs 1

XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts of heap memory is taken. Eventually, the JVM process will run out of memory. Otherwise, if the OS does not bound the memory on that process, memory will continue to be exhausted and will affect other processes on the system.

Package Affected Version
pkg:maven/ro.pippo/pippo-jaxb <= 1.12.0
ID
MAVEN:GHSA-HWCX-9P4J-7HWJ
Severity
high
URL
https://github.com/advisories/GHSA-hwcx-9p4j-7hwj
Published
2019-06-13T20:22:30
(5 years ago)
Modified
2023-02-01T05:02:21
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/ro.pippo/pippo-jaxb ro.pippo pippo-jaxb <= 1.12.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...