CRITICAL9.3
GHSA-vjv6-gq77-3mjw
XXE attack in Mapfish Print
Quick fix
GHSA-vjv6-gq77-3mjw — org.mapfish.print:print-lib: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.24</version> for org.mapfish.print:print-libDetails
### Impact A user can do to an XML External Entity (XXE) attack with the provided SDL style.
### Patches Use version >= 3.24
### Workarounds No
### References * https://cwe.mitre.org/data/definitions/611.html * https://github.com/mapfish/mapfish-print/pull/1397/commits/e1d0527d13db06b2b62ca7d6afb9e97dacd67a0e
### For more information If you have any questions or comments about this advisory Comment the pull request: https://github.com/mapfish/mapfish-print/pull/1397
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.mapfish.print:print-lib
Introduced in:
3.0Fixed in: 3.24Fix
# pom.xml: bump <version>3.24</version> for org.mapfish.print:print-libMaven/org.mapfish.print:print-servlet
Introduced in:
3.0Fixed in: 3.24Fix
# pom.xml: bump <version>3.24</version> for org.mapfish.print:print-servletMaven/org.mapfish.print:print-standalone
Introduced in:
3.0Fixed in: 3.24Fix
# pom.xml: bump <version>3.24</version> for org.mapfish.print:print-standaloneReferences
- https://github.com/mapfish/mapfish-print/security/advisories/GHSA-vjv6-gq77-3mjw[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-15232[ADVISORY]
- https://github.com/mapfish/mapfish-print/pull/1397[WEB]
- https://github.com/mapfish/mapfish-print/pull/1397/commits/e1d0527d13db06b2b62ca7d6afb9e97dacd67a0e[WEB]
- https://github.com/mapfish/mapfish-print[PACKAGE]