VDB
Sign up
CRITICAL9.3

GHSA-vjv6-gq77-3mjw

XXE attack in Mapfish Print

Quick fix

GHSA-vjv6-gq77-3mjw — org.mapfish.print:print-lib: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.24</version> for org.mapfish.print:print-lib

Details

### Impact A user can do to an XML External Entity (XXE) attack with the provided SDL style.

### Patches Use version >= 3.24

### Workarounds No

### References * https://cwe.mitre.org/data/definitions/611.html * https://github.com/mapfish/mapfish-print/pull/1397/commits/e1d0527d13db06b2b62ca7d6afb9e97dacd67a0e

### For more information If you have any questions or comments about this advisory Comment the pull request: https://github.com/mapfish/mapfish-print/pull/1397

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.mapfish.print:print-lib
Introduced in: 3.0Fixed in: 3.24
Fix# pom.xml: bump <version>3.24</version> for org.mapfish.print:print-lib
Maven/org.mapfish.print:print-servlet
Introduced in: 3.0Fixed in: 3.24
Fix# pom.xml: bump <version>3.24</version> for org.mapfish.print:print-servlet
Maven/org.mapfish.print:print-standalone
Introduced in: 3.0Fixed in: 3.24
Fix# pom.xml: bump <version>3.24</version> for org.mapfish.print:print-standalone

References