漏洞信息详情
Apache Xmlbeans 输入验证错误漏洞
漏洞简介
Apache Xmlbeans是美国阿帕奇(Apache)基金会的一款用于支持Java与XMl格式数据进行交互的软件。
Apache Xmlbeans up to version 2.6.0 存在输入验证错误漏洞,该漏洞源于没有设置保护用户免受恶意XML输入伤害所需的属性。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://issues.apache.org/jira/browse/XMLBEANS-517
参考网址
来源:MLIST
链接:https://lists.apache.org/thread.html/rbb01d10512098894cd5f22325588197532c64f1c818ea7e4120d40c1@%3Cjava-dev.axis.apache.org%3E
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210513-0004/
来源:MISC
链接:https://poi.apache.org/
来源:MLIST
链接:https://lists.apache.org/thread.html/r2dc5588009dc9f0310b7382269f932cc96cae4c3901b747dda1a7fed@%3Cjava-dev.axis.apache.org%3E
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/06/msg00024.html
来源:MISC
链接:https://issues.apache.org/jira/browse/XMLBEANS-517
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilites-affect-ibm-jazz-foundation-and-ibm-engineering-products-5/
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Apache-XMLBeans-external-XML-entity-injection-35452
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6495963
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2250
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-planning-analytics-spreadsheet-services-is-affected-by-security-vulnerabilities/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-23926
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-open-source-libraries-affects-tivoli-netcool-omnibus-webgui/
受影响实体
暂无
补丁
- Apache Xmlbeans 输入验证错误漏洞的修复措施<!--2021-1-14-->
还没有评论,来说两句吧...