GHSA-j379-9jr9-w5cq

    Dashboard / Vulnerabilities / GHSA-j379-9jr9-w5cq

    GHSA-j379-9jr9-w5cq

    Published: 21 Dec 2018Last Modified: 8 Nov 2023

    Summary: XML External Entity (XXE) vulnerability in Square Retrofit

    Details: Square Open Source Retrofit versions prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contain a XML External Entity (XXE) vulnerability in JAXB. An attacker could use this to remotely read files from the file system or to perform SSRF. This vulnerability appears to have been fixed in commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437.

    Affected packages

    Package

    Name: com.squareup.retrofit2:retrofit

    Purl: pkg:maven/com.squareup.retrofit2/retrofit

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.0.0
    Fixed -2.5.0

    Affected versions

    2.0.0
    2.0.1
    2.0.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High