Description:

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties 
needed to protect the user from malicious XML input. Vulnerabilities include 
possibilities for XML Entity Expansion attacks.

Affects XMLBeans up to and including v2.6.0.


This issue is being tracked asĀ 
https://issues.apache.org/jira/browse/XMLBEANS-517


References:

https://poi.apache.org/
https://issues.apache.org/jira/browse/XMLBEANS-517

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to