CVE-2019-9843

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
28/06/2019
Last modified:
07/11/2023

Description

In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:diffplug:gradle:*:*:*:*:*:spotless:*:* 3.20.0 (excluding)
cpe:2.3:a:diffplug:maven:*:*:*:*:*:spotless:*:* 1.20.0 (excluding)