CVE-2019-12996: SSRF
Published Sep 10, 2019
·Updated
In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potentially unsafe.
Affected Software
1 affected component
Mendix Mendix<=7.23.5
Event History
Sep 10, 2019
CVE Published
via MITRE·06:43 PM
Data Sourced
via MITRE·06:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Mendix issue?
The vulnerability ID for this Mendix issue is CVE-2019-12996.
2
What is the severity of CVE-2019-12996?
The severity of CVE-2019-12996 is medium with a CVSS score of 5.3.
3
How does Mendix 7.23.5 and earlier versions handle XML import mappings?
Mendix 7.23.5 and earlier versions have an issue in XML import mappings that allow DOCTYPE declarations in the XML input, which can be potentially unsafe.
4
Which versions of Mendix are affected by CVE-2019-12996?
CVE-2019-12996 affects Mendix versions up to and including 7.23.5.
5
How can I fix CVE-2019-12996 in Mendix?
To fix CVE-2019-12996 in Mendix, you should update to a version higher than 7.23.5.