GHSA-2363-cqg2-863c
HIGHCVE-2021-33813An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. As a workaround, to avoid external entities being expanded, one can call builder.setExpandEntities(false) and they won't be expanded.
- Affected
- >=8.8.1, <8.8.2, >=8.9.0, <8.9.1
- Fixed in
- 2.0.6.1
- Weakness
- CWE-611
- Published
- 2021-07-27
- Source
- github