CRITICAL9.8
GHSA-h755-h99p-9ffv
XML External Entity Reference in weixin-java-tools
Quick fix
GHSA-h755-h99p-9ffv — com.github.binarywang:weixin-java-common: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.3.2.B</version> for com.github.binarywang:weixin-java-commonDetails
An issue was discovered in weixin-java-tools. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/com.github.binarywang:weixin-java-common
Introduced in:
0Fixed in: 3.3.2.BFix
# pom.xml: bump <version>3.3.2.B</version> for com.github.binarywang:weixin-java-common