XXE attack in Mapfish Print
Critical severity
GitHub Reviewed
Published
Jul 6, 2020
in
mapfish/mapfish-print
•
Updated Jun 27, 2023
Description
Reviewed
Jul 7, 2020
Published to the GitHub Advisory Database
Jul 7, 2020
Last updated
Jun 27, 2023
Impact
A user can do to an XML External Entity (XXE) attack with the provided SDL style.
Patches
Use version >= 3.24
Workarounds
No
References
For more information
If you have any questions or comments about this advisory Comment the pull request: mapfish/mapfish-print#1397
References