First published: Thu Apr 11 2019(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.opensaml:xmltooling | <3.0.4 | 3.0.4 |
debian/xmltooling | 3.2.0-3+deb11u1 3.2.3-1+deb12u1 3.2.4-2.1 | |
XMLTooling | <3.0.4 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =18.10 | |
openSUSE | =15.0 | |
openSUSE | =42.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9628 has a medium severity due to improper handling of invalid XML data.
To fix CVE-2019-9628, update the XMLTooling library to version 3.0.4 or higher.
CVE-2019-9628 affects all versions of the XMLTooling library prior to 3.0.4.
Yes, CVE-2019-9628 affects Ubuntu versions 14.04, 16.04, 18.04, and 18.10 if they are using the vulnerable XMLTooling library.
CVE-2019-9628 is related specifically to the XMLTooling library included in OpenSAML and Shibboleth Service Provider software.