First published: Wed May 14 2025(Updated: )
Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/github/bonigarcia/wdm/WebDriverManager.java. This issue affects webdrivermanager: from 1.0.0 before 6.1.0.
Credit: cve_disclosure@tech.gov.sg
Affected Software | Affected Version | How to fix |
---|---|---|
bonigarcia webdrivermanager | >=1.0.0<6.0.2 | |
maven/io.github.bonigarcia:webdrivermanager | >=1.0.0<6.1.0 | 6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4641 has a medium severity level, indicating a moderate risk of exploitation.
To fix CVE-2025-4641, update bonigarcia WebDriverManager to a version that is higher than 6.0.2.
CVE-2025-4641 affects systems running bonigarcia WebDriverManager on Windows, MacOS, and Linux.
The impact of CVE-2025-4641 is related to data serialization and potential exposure to XML external entity attacks.
Yes, CVE-2025-4641 can be exploited remotely if the vulnerable software is exposed to untrusted XML input.