Hello  - 
Recently saw this vulnerability 
Apache POI in versions prior to release 3.15 allows remote attackers to 
cause a denial of service (CPU consumption) via a specially crafted OOXML 
file, aka an XML Entity Expansion (XEE) attack. Users with applications 
which accept content from external or untrusted sources are advised to 
upgrade to Apache POI 3.15 or newer. 

We recently migrated to 3.14 a couple of months back. Though 3.14 is 
affected as per the above text, can some one give additional details what 
exactly is this vulnerability and how it affects ?  Does usage of any 
Class or a method or a some particular formatted input affects that ? This 
will be more helpful to us in determining if 3.14 usage really affects or 
not.


---
Thanks in advance
Sateesh 

Reply via email to