First published: Wed Oct 09 2024(Updated: )
Apache XML Graphics FOP is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. By sending specially crafted XML data, a remote attacker could exploit this vulnerability to obtain sensitive information.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.xmlgraphics:fop-core | <=2.9 | 2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28168 is classified as a critical severity vulnerability due to its potential for unauthorized access through XML External Entity injection.
To fix CVE-2024-28168, users should upgrade Apache XML Graphics FOP to version 2.10 or later.
CVE-2024-28168 affects Apache XML Graphics FOP versions up to and including 2.9.
CVE-2024-28168 is an Improper Restriction of XML External Entity Reference (XXE) vulnerability.
Any users and applications utilizing Apache XML Graphics FOP version 2.9 or earlier are impacted by CVE-2024-28168.