Meta tags:
description= GitHub is where people build software. More than 94 million people use GitHub to discover, fork, and contribute to over 330 million projects.;
Headings (most frequently used words):
external, versions, footer, references, id, user, xml, entity, xxe, processing, parameter, entities, feature, was, not, fully, disabled, package, affected, patched, description, impact, patches, workarounds, for, more, information, severity, weaknesses, cve, ghsa, source, code, credits, navigation, build, maintainers, static, analysis, as, service, cvss, base, metrics,
Text of the page (most frequently used words):
github (17), checkstyle (15), the (12), cve (8), that (7), code (7), 2019 (7), you (6), this (6), https (6), #external (6), all (6), for (5), 10782 (5), none (5), 2020 (5), xml (5), xxe (5), jump (5), with (4), vulnerability (4), source (4), ghsa (4), jan (4), advisory (4), org (4), entity (4), are (4), analysis (4), and (4), processing (4), search (4), about (3), security (3), 2022 (3), 763g (3), fqq7 (3), 48wg (3), user (3), open (3), com (3), users (3), fix (3), patched (3), versions (3), should (3), from (3), static (3), run (3), service (3), maven (3), was (3), sign (3), signed (2), another (2), tab (2), window (2), refresh (2), your (2), session (2), reload (2), can (2), perform (2), blog (2), pricing (2), footer (2), navigation (2), cwe (2), 611 (2), cvss (2), low (2), attack (2), moderate (2), severity (2), published (2), lists (2), debian (2), html (2), apache (2), snyk (2), vuln (2), 7468 (2), references (2), issue (2), issues (2), any (2), information (2), there (2), has (2), docker (2), exfiltrate (2), container (2), these (2), flags (2), vulnerabilities (2), tools (2), being (2), 9658 (2), files (2), vulnerable (2), impact (2), reviewed (2), parameter (2), entities (2), feature (2), not (2), fully (2), disabled (2), database (2), manage (2), packages (2), web (2), out, action, time, training, api, contact, docs, status, privacy, terms, inc, see, something, contribute, suggest, improvements, checking, history, jlleitschuh, credits, known, weaknesses, availability, integrity, confidentiality, unchanged, scope, interaction, privileges, required, complexity, network, vector, base, metrics, maintainer, romani, lts, announce, msg00008, thread, r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540, 3ccommits, nifi, java, compuppycrawltools, 543266, nvd, nist, gov, detail, c46a16d, have, questions, comments, more, improper, restriction, reference, workaround, available, way, remediate, without, upgrading, workarounds, will, released, version, problem, been, what, upgrade, patches, running, advantage, sensitive, local, file, additionally, prevent, like, used, data, via, ssrf, jonathan, leitschuh, net, privileged, false, cap, drop, while, looking, few, companies, pmd, ect, notice, common, pattern, tool, inside, following, note, discoverer, original, operate, site, parses, untrusted, configuration, patch, probably, doesn, gradle, most, cases, builds, trusted, pre, vetted, pull, request, reviewer, before, internal, infrastructure, build, maintainers, due, incomplete, still, description, affected, puppycrawl, package, dependabot, alerts, details, updated, apr, message, suggested, results, collections, trending, topics, repositories, community, articles, readme, project, fund, developers, sponsors, resources, customer, stories, case, studies, devsecops, devops, automation, solution, education, startups, teams, enterprise, solutions, skills, documentation, features, explore, collaborate, outside, discussions, plan, track, work, changes, review, write, better, copilot, instant, dev, environments, codespaces, find, host, automate, workflow, actions, product, toggle, skip, content, wayback, machine, http, archive, 20221218123300, advisories, timestamps, capture, fail, success, 2023, 2021, dec, nov, feb, jun, 2026, 901, captures,
Text of the page (random words):
xml external entity xxe processing external parameter entities feature was not fully disabled cve 2019 10782 github advisory database github 901 captures 09 feb 2020 10 jun 2026 nov dec jan 18 2021 2022 2023 success fail about this capture timestamps the wayback machine http web archive org web 20221218123300 https github com advisories ghsa 763g fqq7 48wg skip to content toggle navigation sign up cve 2019 10782 product actions automate any workflow packages host and manage packages security find and fix vulnerabilities codespaces instant dev environments copilot write better code with ai code review manage code changes issues plan and track work discussions collaborate outside of code explore all features documentation github skills blog solutions for enterprise teams startups education by solution ci cd automation devops devsecops case studies customer stories resources open source github sponsors fund open source developers the readme project github community articles repositories topics trending collections pricing search all github jump to no suggested jump to results search all github jump to search all github jump to search all github jump to sign in sign up message github advisory database github reviewed cve 2019 10782 xml external entity xxe processing external parameter entities feature was not fully disabled moderate severity github reviewed published jan 31 2020 in checkstyle checkstyle updated apr 19 2022 vulnerability details dependabot alerts 0 package maven com puppycrawl tools checkstyle maven affected versions 8 29 patched versions 8 29 description due to an incomplete fix for cve 2019 9658 checkstyle was still vulnerable to xml external entity xxe processing impact user build maintainers this vulnerability probably doesn t impact maven gradle users as in most cases these builds are processing files that are trusted or pre vetted by a pull request reviewer before being run on internal ci infrastructure user static analysis as a service if you operate a site service that parses untrusted checkstyle xml configuration files you are vulnerable to this and should patch note from the discoverer of the original cve 2019 9658 while looking at a few companies that run checkstyle pmd ect as a service i notice that it s a common pattern to run the static code analysis tool inside of a docker container with the following flags net none privileged false cap drop all running the analysis in docker has the advantage that there should be no sensitive local file information that xxe can exfiltrate from the container additionally these flags prevent vulnerabilities in static analysis tools like checkstyle from being used to exfiltrate data via xxe or to perform ssrf jonathan leitschuh patches has the problem been patched what versions should users upgrade to patched will be released with version 8 29 at 26 jan 2020 workarounds is there a way for users to fix or remediate the vulnerability without upgrading no workaround are available references cwe 611 improper restriction of xml external entity reference github issue checkstyle checkstyle 7468 for more information if you have any questions or comments about this advisory open an issue in https github com checkstyle checkstyle issues references ghsa 763g fqq7 48wg checkstyle checkstyle 7468 checkstyle checkstyle c46a16d https nvd nist gov vuln detail cve 2019 10782 https snyk io vuln snyk java compuppycrawltools 543266 https lists apache org thread html r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540 3ccommits nifi apache org 3e https lists debian org debian lts announce 2020 02 msg00008 html romani published the maintainer security advisory jan 31 2020 severity moderate 5 3 10 cvss base metrics attack vector network attack complexity low privileges required none user interaction none scope unchanged confidentiality low integrity none availability none cvss 3 1 av n ac l pr n ui n s u c l i n a n weaknesses cwe 611 cve id cve 2019 10782 ghsa id ghsa 763g fqq7 48wg source code no known source code credits jlleitschuh checking history see something to contribute suggest improvements for this vulnerability footer 2022 github inc footer navigation terms privacy security status docs contact github pricing api training blog about you can t perform that action at this time you signed in with another tab or window reload to refresh your session you signed out in another tab or window reload to refresh your session
|