Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-0198: Fix SAXParser security issue · stanfordnlp/CoreNLP@1f52136

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

CVE
#java

@@ -5,6 +5,7 @@

import java.io.*;

import java.util.*;

import javax.xml.XMLConstants;

import javax.xml.parsers.SAXParser;

import javax.xml.parsers.SAXParserFactory;

@@ -195,6 +196,8 @@ public void processText(String text) {

public TransformXML() {

try {

SAXParserFactory spf = SAXParserFactory.newInstance();

spf.setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true);

saxParser = SAXParserFactory.newInstance().newSAXParser();

} catch (Exception e) {

log.info("Error configuring XML parser: " + e);

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907