GHSA-7v35-qwwj-p98g

    Dashboard / Vulnerabilities / GHSA-7v35-qwwj-p98g

    GHSA-7v35-qwwj-p98g

    Published: 5 Jul 2019Last Modified: 8 Nov 2023
    Aliases:

    Summary: Improper Restriction of XML External Entity Reference in DiffPlug Spotless

    Details: In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file.

    Affected packages

    Package

    Name: com.diffplug.spotless:spotless-plugin-gradle

    Purl: pkg:maven/com.diffplug.spotless/spotless-plugin-gradle

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.20.0

    Affected versions

    3.0.0
    3.0.0.BETA2
    3.0.0.BETA3
    3.0.0.RC1
    3.0.0.RC2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High