Description:

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties 
needed to protect the user from malicious XML input. Vulnerabilities include 
possibilities for XML Entity Expansion attacks.

Affects XMLBeans up to and including v2.6.0. It is recommended to upgrade to at 
least v3.0.0 but v4.0.0 is recommended. This upgrade is not expected to be 
difficult for most users.


This issue is being tracked asĀ 
https://issues.apache.org/jira/browse/XMLBEANS-517


References:

https://poi.apache.org/
https://issues.apache.org/jira/browse/XMLBEANS-517

Reply via email to