GHSA-wrx5-rp7m-mm49
Dashboard / Vulnerabilities / GHSA-wrx5-rp7m-mm49
Summary: Withdrawn: CVE Rejected: JXPath vulnerable to remote code execution when interpreting untrusted XPath expressions
Details: ## This advisory has been withdrawn due to the CVE being rejected. ## Original advisory text Those using JXPath to interpret untrusted XPath expressions may be vulnerable to a remote code execution attack. All JXPathContext class functions processing a XPath string are vulnerable except `compile()` and `compilePath()` function. The XPath expression can be used by an attacker to load any Java class from the classpath resulting in code execution.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-41852, https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47133, https://commons.apache.org/proper/commons-jxpath/users-guide.html#Standard_Extension_Functions, https://github.com/apache/commons-jxpath, https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852
Affected packages
Package
Name: commons-jxpath:commons-jxpath
Purl: pkg:maven/commons-jxpath/commons-jxpath
Affected ranges
Type: ECOSYSTEM
Events:
