First published: Thu Jan 30 2020(Updated: )
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Checkstyle | <8.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10782 is classified as a critical vulnerability due to its potential for XML External Entity (XXE) Injection attacks.
To fix CVE-2019-10782, you should upgrade to versions of Checkstyle after 8.29, where this vulnerability is resolved.
All versions of Checkstyle before 8.29 are affected by CVE-2019-10782.
CVE-2019-10782 involves XML External Entity (XXE) Injection vulnerabilities.
Yes, CVE-2019-10782 is related to an incomplete fix for CVE-2019-9658.