[MAVEN:GHSA-JVFV-HRRC-6Q72] Improper Restriction of XML External Entity Reference in Liquibase

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

The XMLChangeLogSAXParser() function in Liquibase prior to version 4.8.0 contains an issue that may lead to to Improper Restriction of XML External Entity Reference.

Package Affected Version
pkg:maven/org.liquibase/liquibase-core < 4.8.0
Package Fixed Version
pkg:maven/org.liquibase/liquibase-core = 4.8.0
ID
MAVEN:GHSA-JVFV-HRRC-6Q72
Severity
critical
URL
https://github.com/advisories/GHSA-jvfv-hrrc-6q72
Published
2022-03-05T00:00:45
(2 years ago)
Modified
2023-01-27T05:02:46
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.liquibase/liquibase-core org.liquibase liquibase-core < 4.8.0
Fixed pkg:maven/org.liquibase/liquibase-core org.liquibase liquibase-core = 4.8.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...