{"id":"GHSA-86p9-x5pw-94qx","summary":"Improper Restriction of XML External Entity Reference in  iText","details":"The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.","aliases":["CVE-2017-9096"],"modified":"2024-03-06T22:01:55.457317Z","published":"2022-05-13T01:14:24Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-06-30T19:51:56Z","nvd_published_at":"2017-11-08T16:29:00Z","cwe_ids":["CWE-611"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9096"},{"type":"WEB","url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us"},{"type":"WEB","url":"https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2017-017_itext_xml_external_entity_attack.txt"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/541483/100/0/threaded"}],"affected":[{"package":{"name":"com.itextpdf:itextpdf","ecosystem":"Maven","purl":"pkg:maven/com.itextpdf/itextpdf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.5.12"}]}],"versions":["5.0.6","5.1.0","5.1.1","5.1.2","5.1.3","5.2.0","5.2.1","5.3.0","5.3.1","5.3.2","5.3.4","5.4.0","5.4.1","5.4.2","5.4.3","5.4.4","5.4.5","5.5.0","5.5.1","5.5.10","5.5.11","5.5.2","5.5.3","5.5.4","5.5.5","5.5.6","5.5.7","5.5.8","5.5.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-86p9-x5pw-94qx/GHSA-86p9-x5pw-94qx.json"}},{"package":{"name":"com.itextpdf:itextpdf","ecosystem":"Maven","purl":"pkg:maven/com.itextpdf/itextpdf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-86p9-x5pw-94qx/GHSA-86p9-x5pw-94qx.json"}},{"package":{"name":"com.lowagie:itext","ecosystem":"Maven","purl":"pkg:maven/com.lowagie/itext"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.2.2"}]}],"versions":["0.99","1.02b","1.1.4","1.2.3","1.3","1.3.1","1.4","1.4.8","2.0.1","2.0.6","2.0.7","2.0.8","2.1.0","2.1.2","2.1.3","2.1.4","2.1.5","2.1.7","4.2.0","4.2.1","4.2.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-86p9-x5pw-94qx/GHSA-86p9-x5pw-94qx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}