rsyntaxtextarea is vulnerable to Improper Restriction of XML External Entity Reference
58
Medium Risk
Affected versions of this package are vulnerable to XML External Entity (XXE) injection due to insecure XML deserialization in the load() function in Theme.java. The code uses an SAXParserFactory without explicitly disabling external entity resolution, allowing an attacker to supply a crafted XML payload containing external entity references. This can result in unauthorized file access, server-side request forgery, or denial of service through resource exhaustion.
You are affected if you are using a version that falls within the vulnerable range.
rsyntaxtextarea is vulnerable to Improper Restriction of XML External Entity Reference in versions 0.0.1 - 3.6.0.
Upgrade the com.fifesoft:rsyntaxtextarea library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant