CVE-2017-18197: XEE
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
Other sources
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18197?
CVE-2017-18197 is classified as a medium-severity vulnerability due to its potential for XML External Entity (XXE) attacks.
How do I fix CVE-2017-18197?
To fix CVE-2017-18197, upgrade mxGraph to version 3.7.6 or later.
What software is affected by CVE-2017-18197?
CVE-2017-18197 affects mxGraph versions before 3.7.6, including all prior versions up to 3.7.5.
What type of attack does CVE-2017-18197 expose systems to?
CVE-2017-18197 exposes systems to XML External Entity (XXE) attacks, which can lead to disclosure of confidential data.
Is there a workaround for CVE-2017-18197?
There are no known workarounds for CVE-2017-18197; the recommended action is to update the software.