Improper Restriction of XML External Entity Reference in com.monitorjbl:xlsx-streamer
Critical severity
GitHub Reviewed
Published
Mar 2, 2022
in
monitorjbl/excel-streaming-reader
•
Updated Jul 24, 2023
Description
Published by the National Vulnerability Database
Mar 2, 2022
Published to the GitHub Advisory Database
Mar 2, 2022
Reviewed
Mar 2, 2022
Last updated
Jul 24, 2023
Impact
Prior to xlsx-streamer 2.1.0, the XML parser that was used did not apply all the necessary settings to prevent XML Entity Expansion issues.
Patches
Upgrade to version 2.1.0.
Workarounds
No known workaround.
References
monitorjbl/excel-streaming-reader@0749c7b
For more information
If you have any questions or comments about this advisory:
References