GHSA-85hw-w436-c725
HIGHCVE-2018-11758This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shipped with Apache Cayenne and intended for editing Cayenne ORM models stored as XML files. If an attacker tricks a user of CayenneModeler into opening a malicious XML file, the attacker will be able to instruct the XML parser built into CayenneModeler to
- Affected
- < 3.1.3, >= 4.0, < 4.1
- Fixed in
- 3.1.3
- Weakness
- CWE-611
- Published
- 2022-05-14
- Source
- github