CRITICAL9.8
GHSA-6fvx-r7hx-3vh6
JavaMelody has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.
Quick fix
GHSA-6fvx-r7hx-3vh6 — net.bull.javamelody:javamelody-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.74.0</version> for net.bull.javamelody:javamelody-coreDetails
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/net.bull.javamelody:javamelody-core
Introduced in:
0Fixed in: 1.74.0Fix
# pom.xml: bump <version>1.74.0</version> for net.bull.javamelody:javamelody-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2018-15531[ADVISORY]
- https://github.com/javamelody/javamelody/commit/ef111822562d0b9365bd3e671a75b65bd0613353[WEB]
- https://github.com/advisories/GHSA-6fvx-r7hx-3vh6[ADVISORY]
- https://github.com/javamelody/javamelody[PACKAGE]
- https://github.com/javamelody/javamelody/wiki/ReleaseNotes[WEB]
- https://jenkins.io/security/advisory/2018-09-25[WEB]
- http://www.openwall.com/lists/oss-security/2018/09/25/3[WEB]