XML External Entity Reference in weixin-java-tools
Critical severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Jan 8, 2024
Package
Affected versions
< 3.3.2.B
Patched versions
3.3.2.B
Description
Published by the National Vulnerability Database
Jan 4, 2019
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jan 8, 2024
Last updated
Jan 8, 2024
An issue was discovered in weixin-java-tools. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318.
References