Sploitus

CVE-2017-12620

4 known exploits for CVE-2017-12620

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.

Affected products
Apache Opennlp
Apache Opennlp
= 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.6.0, 1.7.0, 1.7.1, 1.7.2, 1.8.0, 1.8.1
Fix
Available
CVSS 3.0
9.8 CRITICAL
EPSS
3.0% (86th percentile)
Weakness
CWE-611
NVD status
Modified
Published
2017-10-02
CVE-2017-12620 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2017-12620

Proof-of-concept code and exploit modules indexed by Sploitus