Improper Restriction of XML External Entity Reference in Apache POI
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Oct 23, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jun 28, 2022
Last updated
Jan 28, 2023
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
References