mpxj is vulnerable to XML External Entity (XXE) Injection
75
High Risk
MPXJ parses XML from Merlin project files using a default DocumentBuilder configuration that does not disable external entity resolution. A crafted Merlin file can declare external entities that cause the reader to resolve them while parsing. Before the fix this could read arbitrary files on the host during processing, though reliable exfiltration is limited by how the resulting data is handled. The fix hardens the XML reader to reject external entity references.
You are affected if you are using a version that falls within the vulnerable range and you use MPXJ to read untrusted Merlin project files.
mpxj is vulnerable to XML External Entity (XXE) Injection in versions 5.5.5 - 16.4.0.
Upgrade the net.sf.mpxj:mpxj library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant