GHSA-xvm2-9xvc-hx7f
Dashboard / Vulnerabilities / GHSA-xvm2-9xvc-hx7f
Summary: Improper Restriction of XML External Entity Reference in com.monitorjbl:xlsx-streamer
Details: ### Impact Prior to xlsx-streamer 2.1.0, the XML parser that was used did not apply all the necessary settings to prevent XML Entity Expansion issues. ### Patches Upgrade to version 2.1.0. ### Workarounds No known workaround. ### References https://github.com/monitorjbl/excel-streaming-reader/commit/0749c7b9709db078ccdeada16d46a34bc2910c73 ### For more information If you have any questions or comments about this advisory: * Open an issue in [monitorjbl/excel-streaming-reader](https://github.com/monitorjbl/excel-streaming-reader)
References: https://github.com/monitorjbl/excel-streaming-reader/security/advisories/GHSA-xvm2-9xvc-hx7f, https://nvd.nist.gov/vuln/detail/CVE-2022-23640, https://github.com/monitorjbl/excel-streaming-reader/commit/0749c7b9709db078ccdeada16d46a34bc2910c73, https://github.com/monitorjbl/excel-streaming-reader
Affected packages
Package
Name: com.monitorjbl:xlsx-streamer
Purl: pkg:maven/com.monitorjbl/xlsx-streamer
Affected ranges
Type: ECOSYSTEM
Events:
