CVE-2019-12415

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:poi:*:*:*:*:*:*:*:*

Information

Published : 2019-10-23 20:15

Updated : 2021-10-20 11:15


NVD link : CVE-2019-12415

Mitre link : CVE-2019-12415


JSON object : View

Products Affected

apache

  • poi
CWE
CWE-611

Improper Restriction of XML External Entity Reference