CVE-2023-41034

    Dashboard / Vulnerabilities / CVE-2023-41034

    CVE-2023-41034

    Published: 31 Aug 2023Last Modified: 12 Aug 2026

    Summary: DDFFileParser in eclipse leshan is vulnerable to XXE Attacks

    Details: Eclipse Leshan is a device management server and client Java implementation. In affected versions DDFFileParser` and `DefaultDDFFileValidator` (and so `ObjectLoader`) are vulnerable to `XXE Attacks`. A DDF file is a LWM2M format used to store LWM2M object description. Leshan users are impacted only if they parse untrusted DDF files (e.g. if they let external users provide their own model), in that case they MUST upgrade to fixed version. If you parse only trusted DDF file and validate only with trusted xml schema, upgrading is not mandatory. This issue has been fixed in versions 1.5.0 and 2.0.0-M13. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    2.0.0-milestone1
    2.0.0-milestone10
    2.0.0-milestone11
    2.0.0-milestone12
    2.0.0-milestone2
    2.0.0-milestone3
    2.0.0-milestone4
    2.0.0-milestone5
    2.0.0-milestone6
    2.0.0-milestone7
    2.0.0-milestone8
    2.0.0-milestone9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-41034 | CVE-DB