CRITICAL9.8
GHSA-wvpv-8524-wg6x
mxGraph vulnerable to XXE attacks
Quick fix
GHSA-wvpv-8524-wg6x — mxgraph: upgrade to the fixed version with the command below.
npm install mxgraph@3.7.6Details
In `mxGraphViewImageReader.java` in mxGraph before 3.7.6, the `SAXParserFactory` instance in `convert()` is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by `/ServerView`.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-18197[ADVISORY]
- https://github.com/jgraph/mxgraph/issues/124[WEB]
- https://github.com/jgraph/mxgraph/commit/97b3718db64a6ca9afb3382de2926eb8da660052[WEB]
- https://github.com/jgraph/mxgraph[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2018/03/msg00002.html[WEB]