Vulnerability Description
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkstyle | Checkstyle | < 8.29 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b
- https://lists.debian.org/debian-lts-announce/2020/02/msg00008.html
- https://snyk.io/vuln/SNYK-JAVA-COMPUPPYCRAWLTOOLS-543266ExploitThird Party Advisory
- https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b
- https://lists.debian.org/debian-lts-announce/2020/02/msg00008.html
- https://snyk.io/vuln/SNYK-JAVA-COMPUPPYCRAWLTOOLS-543266ExploitThird Party Advisory
FAQ
What is CVE-2019-10782?
CVE-2019-10782 is a vulnerability with a CVSS score of 5.3 (MEDIUM). All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
How severe is CVE-2019-10782?
CVE-2019-10782 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10782?
Check the references section above for vendor advisories and patch information. Affected products include: Checkstyle Checkstyle.