{"id":"GHSA-5wfp-8643-c58x","summary":"Improper Input Validation in Apache POI","details":"Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.","aliases":["CVE-2014-3574"],"modified":"2024-12-08T05:26:22.777754Z","published":"2022-05-17T01:24:36Z","database_specific":{"cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-07-07T22:41:49Z","nvd_published_at":"2014-09-04T17:55:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3574"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95768"},{"type":"PACKAGE","url":"https://github.com/apache/poi"},{"type":"WEB","url":"https://lucene.apache.org/solr/solrnews.html#18-august-2014-recommendation-to-update-apache-poi-in-apache-solr-480-481-and-490-installations"},{"type":"WEB","url":"https://svn.apache.org/repos/asf/poi/branches/REL_3_10_BRANCH@1616509"},{"type":"WEB","url":"https://svn.apache.org/repos/asf/poi/trunk@1615720"},{"type":"WEB","url":"https://svn.apache.org/repos/asf/poi/trunk@1615731"},{"type":"WEB","url":"https://svn.apache.org/repos/asf/poi/trunk@1615781"},{"type":"WEB","url":"http://poi.apache.org/changes.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1370.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1398.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1399.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1400.html"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21996759"},{"type":"WEB","url":"http://www.apache.org/dist/poi/release/RELEASE-NOTES.txt"}],"affected":[{"package":{"name":"org.apache.poi:poi","ecosystem":"Maven","purl":"pkg:maven/org.apache.poi/poi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.1"}]}],"versions":["3.0-FINAL","3.0.1-FINAL","3.0.2-FINAL","3.0.2-beta1","3.0.2-beta2","3.1-FINAL","3.1-beta1","3.1-beta2","3.10-FINAL","3.10-beta1","3.10-beta2","3.2-FINAL","3.5-FINAL","3.5-beta1","3.5-beta3","3.5-beta4","3.5-beta5","3.5-beta6","3.6","3.7","3.7-beta1","3.7-beta2","3.7-beta3","3.8","3.8-beta1","3.8-beta2","3.8-beta3","3.8-beta4","3.8-beta5","3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5wfp-8643-c58x/GHSA-5wfp-8643-c58x.json"}},{"package":{"name":"org.apache.poi:poi","ecosystem":"Maven","purl":"pkg:maven/org.apache.poi/poi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.11-beta1"},{"fixed":"3.11-beta2"}]}],"versions":["3.11-beta1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5wfp-8643-c58x/GHSA-5wfp-8643-c58x.json"}}],"schema_version":"1.9.0"}