WS-2018-0629 (High) detected in woodstox-core-5.0.2.jar, woodstox-core-5.1.0.jar - autoclosed #324
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
WS-2018-0629 - High Severity Vulnerability
Vulnerable Libraries - woodstox-core-5.0.2.jar, woodstox-core-5.1.0.jar
woodstox-core-5.0.2.jar
Woodstox is a high-performance XML processor that implements Stax (JSR-173), SAX2 and Stax2 APIs
Library home page: https://github.com/FasterXML/woodstox
Path to dependency file: /dd-java-agent/instrumentation/mule-4/mule-4.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.fasterxml.woodstox/woodstox-core/5.0.2/47cf6e83bf5842662cd5eea999eb139904f21bca/woodstox-core-5.0.2.jar
Dependency Hierarchy:
woodstox-core-5.1.0.jar
Woodstox is a high-performance XML processor that implements Stax (JSR-173), SAX2 and Stax2 APIs
Library home page: https://github.com/FasterXML/woodstox
Path to dependency file: /dd-java-agent/instrumentation/jax-rs-client-2.0/jax-rs-client-2.0.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.fasterxml.woodstox/woodstox-core/5.1.0/bd416e84cbd20cb5f2cf13c30b023e814a4d6107/woodstox-core-5.1.0.jar
Dependency Hierarchy:
Found in HEAD commit: 2819174635979a19573ec0ce8e3e2b63a3848079
Found in base branch: master
Vulnerability Details
The woodstox-core package is vulnerable to improper restriction of XXE reference.
Publish Date: 2018-08-23
URL: WS-2018-0629
CVSS 3 Score Details (9.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Release Date: 2018-08-23
Fix Resolution (com.fasterxml.woodstox:woodstox-core): 5.2.1
Direct dependency fix Resolution (org.apache.cxf:cxf-rt-rs-client): 3.2.7
⛑️ Automatic Remediation is available for this issue
The text was updated successfully, but these errors were encountered: