CVE-2023-45960: High severity Dom4j Project Dom4j vulnerability
Withdrawn Advisory This advisory has been withdrawn because the underlying vulnerability could not be reproduced. This link is maintained to preserve external references.
Original Description An issue in dom4.j org.dom4.io.SAXReader v.2.1.4 and before allows a remote attacker to obtain sensitive information via the setFeature function.
Other sources
An issue in dom4.j org.dom4.io.SAXReader v.2.1.4 and before allows a remote attacker to obtain sensitive information via the setFeature function. NOTE: the vendor and original reporter indicate that this is not a vulnerability because setFeature only sets features, which "can be safe in one case and unsafe in another."
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-45960.
What is the affected software?
The affected software is org.dom4j:dom4j version 2.1.4 and earlier.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by obtaining sensitive information through the setFeature function.
Is this vulnerability considered a security risk?
Yes, this vulnerability allows a remote attacker to obtain sensitive information, making it a security risk.
Are there any available patches or fixes for this vulnerability?
There are no known patches or fixes available at the moment. It is recommended to update to a version of org.dom4j:dom4j that is not vulnerable.