PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or MITM attacks when using remote rulesets) to perform information disclosure, denial of service, or request forgery attacks. (PMD 6.x is unaffected because of a 2017-09-15 change.)
References
Link Resource
https://github.com/pmd/pmd/issues/1650 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-02-11T14:00:00

Updated: 2019-02-11T14:57:01

Reserved: 2019-02-11T00:00:00


Link: CVE-2019-7722

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-02-11T14:29:00.217

Modified: 2019-02-21T15:01:03.207


Link: CVE-2019-7722

JSON object: View

cve-icon Redhat Information

No data.

CWE