iText RUPS XML External Entity vulnerability
Critical severity
GitHub Reviewed
Published
Dec 30, 2022
to the GitHub Advisory Database
•
Updated Oct 20, 2023
Description
Published by the National Vulnerability Database
Dec 30, 2022
Published to the GitHub Advisory Database
Dec 30, 2022
Reviewed
Jan 10, 2023
Last updated
Oct 20, 2023
A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file
src/main/java/com/itextpdf/rups/model/XfaFile.java
. The manipulation leads to xml external entity reference. The name of the patch is ac5590925874ef810018a6b60fec216eee54fb32. It is recommended to apply a patch to fix this issue. VDB-217054 is the identifier assigned to this vulnerability.References