If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: web.archive.org/web/20221218123300/https://github.com/advisories/GHSA-763g-fqq7-48wg - maven.

site address: web.archive.org/web/20221218011249/https://github.com/advisories/GHSA-763g-fqq7-48wg redirected to: web.archive.org/web/20221218123300/https://github.com/advisories/GHSA-763g-fqq7-48wg

site title: maven

Our opinion (on Thursday 17 September 2026 17:03:20 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:
description=GitHub is where people build software. More than 94 million people use GitHub to discover, fork, and contribute to over 330 million projects.;

Headings (most frequently used words):

external, versions, footer, references, id, user, xml, entity, xxe, processing, parameter, entities, feature, was, not, fully, disabled, package, affected, patched, description, impact, patches, workarounds, for, more, information, severity, weaknesses, cve, ghsa, source, code, credits, navigation, build, maintainers, static, analysis, as, service, cvss, base, metrics,

Text of the page (most frequently used words):
github (17), checkstyle (15), the (12), cve (8), that (7), code (7), 2019 (7), you (6), this (6), https (6), #external (6), all (6), for (5), 10782 (5), none (5), 2020 (5), xml (5), xxe (5), jump (5), with (4), vulnerability (4), source (4), ghsa (4), jan (4), advisory (4), org (4), entity (4), are (4), analysis (4), and (4), processing (4), search (4), about (3), security (3), 2022 (3), 763g (3), fqq7 (3), 48wg (3), user (3), open (3), com (3), users (3), fix (3), patched (3), versions (3), should (3), from (3), static (3), run (3), service (3), maven (3), was (3), sign (3), signed (2), another (2), tab (2), window (2), refresh (2), your (2), session (2), reload (2), can (2), perform (2), blog (2), pricing (2), footer (2), navigation (2), cwe (2), 611 (2), cvss (2), low (2), attack (2), moderate (2), severity (2), published (2), lists (2), debian (2), html (2), apache (2), snyk (2), vuln (2), 7468 (2), references (2), issue (2), issues (2), any (2), information (2), there (2), has (2), docker (2), exfiltrate (2), container (2), these (2), flags (2), vulnerabilities (2), tools (2), being (2), 9658 (2), files (2), vulnerable (2), impact (2), reviewed (2), parameter (2), entities (2), feature (2), not (2), fully (2), disabled (2), database (2), manage (2), packages (2), web (2), out, action, time, training, api, contact, docs, status, privacy, terms, inc, see, something, contribute, suggest, improvements, checking, history, jlleitschuh, credits, known, weaknesses, availability, integrity, confidentiality, unchanged, scope, interaction, privileges, required, complexity, network, vector, base, metrics, maintainer, romani, lts, announce, msg00008, thread, r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540, 3ccommits, nifi, java, compuppycrawltools, 543266, nvd, nist, gov, detail, c46a16d, have, questions, comments, more, improper, restriction, reference, workaround, available, way, remediate, without, upgrading, workarounds, will, released, version, problem, been, what, upgrade, patches, running, advantage, sensitive, local, file, additionally, prevent, like, used, data, via, ssrf, jonathan, leitschuh, net, privileged, false, cap, drop, while, looking, few, companies, pmd, ect, notice, common, pattern, tool, inside, following, note, discoverer, original, operate, site, parses, untrusted, configuration, patch, probably, doesn, gradle, most, cases, builds, trusted, pre, vetted, pull, request, reviewer, before, internal, infrastructure, build, maintainers, due, incomplete, still, description, affected, puppycrawl, package, dependabot, alerts, details, updated, apr, message, suggested, results, collections, trending, topics, repositories, community, articles, readme, project, fund, developers, sponsors, resources, customer, stories, case, studies, devsecops, devops, automation, solution, education, startups, teams, enterprise, solutions, skills, documentation, features, explore, collaborate, outside, discussions, plan, track, work, changes, review, write, better, copilot, instant, dev, environments, codespaces, find, host, automate, workflow, actions, product, toggle, skip, content, wayback, machine, http, archive, 20221218123300, advisories, timestamps, capture, fail, success, 2023, 2021, dec, nov, feb, jun, 2026, 901, captures,


Text of the page (random words):
xml external entity xxe processing external parameter entities feature was not fully disabled cve 2019 10782 github advisory database github 901 captures 09 feb 2020 10 jun 2026 nov dec jan 18 2021 2022 2023 success fail about this capture timestamps the wayback machine http web archive org web 20221218123300 https github com advisories ghsa 763g fqq7 48wg skip to content toggle navigation sign up cve 2019 10782 product actions automate any workflow packages host and manage packages security find and fix vulnerabilities codespaces instant dev environments copilot write better code with ai code review manage code changes issues plan and track work discussions collaborate outside of code explore all features documentation github skills blog solutions for enterprise teams startups education by solution ci cd automation devops devsecops case studies customer stories resources open source github sponsors fund open source developers the readme project github community articles repositories topics trending collections pricing search all github jump to no suggested jump to results search all github jump to search all github jump to search all github jump to sign in sign up message github advisory database github reviewed cve 2019 10782 xml external entity xxe processing external parameter entities feature was not fully disabled moderate severity github reviewed published jan 31 2020 in checkstyle checkstyle updated apr 19 2022 vulnerability details dependabot alerts 0 package maven com puppycrawl tools checkstyle maven affected versions 8 29 patched versions 8 29 description due to an incomplete fix for cve 2019 9658 checkstyle was still vulnerable to xml external entity xxe processing impact user build maintainers this vulnerability probably doesn t impact maven gradle users as in most cases these builds are processing files that are trusted or pre vetted by a pull request reviewer before being run on internal ci infrastructure user static analysis as a service if you operate a site service that parses untrusted checkstyle xml configuration files you are vulnerable to this and should patch note from the discoverer of the original cve 2019 9658 while looking at a few companies that run checkstyle pmd ect as a service i notice that it s a common pattern to run the static code analysis tool inside of a docker container with the following flags net none privileged false cap drop all running the analysis in docker has the advantage that there should be no sensitive local file information that xxe can exfiltrate from the container additionally these flags prevent vulnerabilities in static analysis tools like checkstyle from being used to exfiltrate data via xxe or to perform ssrf jonathan leitschuh patches has the problem been patched what versions should users upgrade to patched will be released with version 8 29 at 26 jan 2020 workarounds is there a way for users to fix or remediate the vulnerability without upgrading no workaround are available references cwe 611 improper restriction of xml external entity reference github issue checkstyle checkstyle 7468 for more information if you have any questions or comments about this advisory open an issue in https github com checkstyle checkstyle issues references ghsa 763g fqq7 48wg checkstyle checkstyle 7468 checkstyle checkstyle c46a16d https nvd nist gov vuln detail cve 2019 10782 https snyk io vuln snyk java compuppycrawltools 543266 https lists apache org thread html r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540 3ccommits nifi apache org 3e https lists debian org debian lts announce 2020 02 msg00008 html romani published the maintainer security advisory jan 31 2020 severity moderate 5 3 10 cvss base metrics attack vector network attack complexity low privileges required none user interaction none scope unchanged confidentiality low integrity none availability none cvss 3 1 av n ac l pr n ui n s u c l i n a n weaknesses cwe 611 cve id cve 2019 10782 ghsa id ghsa 763g fqq7 48wg source code no known source code credits jlleitschuh checking history see something to contribute suggest improvements for this vulnerability footer 2022 github inc footer navigation terms privacy security status docs contact github pricing api training blog about you can t perform that action at this time you signed in with another tab or window reload to refresh your session you signed out in another tab or window reload to refresh your session
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • loading
  • @romani
  • @JLLeitschuh

Verified site has: 61 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-61


The site also has references to the 2 subdomain(s)

  archive.org  Verify   help.archive.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 302 FOUND
Server nginx
Date Thu, 17 Sep 2026 17:03:19 GMT
Content-Type text/plain; charset=utf-8
Content-Length 0
Connection close
x-archive-redirect-reason found capture at 20221218123300
location htt???/web.archive.org/web/20221218123300/htt????/github.com/advisories/GHSA-763g-fqq7-48wg
server-timing captures_list;dur=0.419762, exclusion.robots;dur=0.046367, exclusion.robots.policy;dur=0.037996, esindex;dur=0.006832, cdx.remote;dur=13.255308, LoadShardBlock;dur=764.923376, PetaboxLoader3.datanode;dur=739.030537
x-app-server wwwb-app54-dc6
x-ts 302
x-tr 828
server-timing TR;dur=0,Tw;dur=0,Tc;dur=0
set-cookie wb-p-SERVER=wwwb-app54; path=/
X-location All
X-AS 16276
X-RL 0
X-NA 0
X-Page-Cache MISS
Server-Timing MISS
X-NID OVH SAS
Referrer-Policy no-referrer-when-downgrade
Permissions-Policy interest-cohort=()
X-sd 0
HTTP/1.1 200 OK
Server nginx
Date Thu, 17 Sep 2026 17:03:21 GMT
Content-Type text/html; charset=utf-8
Transfer-Encoding chunked
Connection close
x-archive-orig-server GitHub.com
x-archive-orig-date Sun, 18 Dec 2022 12:33:01 GMT
x-archive-orig-vary X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, Accept-Encoding, Accept, X-Requested-With
x-archive-orig-etag W/ 2c152f2bbc5e4e3b45d3df895f9cedf7
x-archive-orig-cache-control max-age=0, private, must-revalidate
x-archive-orig-strict-transport-security max-age=31536000; includeSubdomains; preload
x-archive-orig-x-frame-options deny
x-archive-orig-x-content-type-options nosniff
x-archive-orig-x-xss-protection 0
x-archive-orig-referrer-policy origin-when-cross-origin, strict-origin-when-cross-origin
x-archive-orig-content-security-policy default-src none ; base-uri self ; block-all-mixed-content; child-src github.com/assets-cdn/worker/ gist.github.com/assets-cdn/worker/; connect-src self uploads.github.com objects-origin.githubusercontent.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com cdn.optimizely.com logx.optimizely.com/v1/events *.actions.githubusercontent.com wss://*.actions.githubusercontent.com online.visualstudio.com/api/v1/locations github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com; font-src github.githubassets.com; form-action self github.com gist.github.com objects-origin.githubusercontent.com; frame-ancestors none ; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src self data: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com objects-origin.githubusercontent.com secured-user-images.githubusercontent.com/ opengraph.githubassets.com github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com *.githubusercontent.com; manifest-src self ; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/; script-src github.githubassets.com; style-src unsafe-inline github.githubassets.com; worker-src github.com/assets-cdn/worker/ gist.github.com/assets-cdn/worker/
x-archive-orig-accept-ranges bytes
x-archive-orig-x-github-request-id AF24:4BA5:2AB188E:3D397D4:639F087C
x-archive-orig-connection close
x-archive-guessed-content-type text/html
x-archive-guessed-charset utf-8
memento-datetime Sun, 18 Dec 2022 12:33:00 GMT
link <htt????/github.com/advisories/GHSA-763g-fqq7-48wg>; rel= original , <htt???/web.archive.org/web/timemap/link/htt????/github.com/advisories/GHSA-763g-fqq7-48wg>; rel= timemap ; type= application/link-format , <htt???/web.archive.org/web/htt????/github.com/advisories/GHSA-763g-fqq7-48wg>; rel= timegate , <htt???/web.archive.org/web/20200209203848/htt????/github.com/advisories/GHSA-763g-fqq7-48wg>; rel= first memento ; datetime= Sun, 09 Feb 2020 20:38:48 GMT , <htt???/web.archive.org/web/20221217121355/htt????/github.com/advisories/GHSA-763g-fqq7-48wg>; rel= prev memento ; datetime= Sat, 17 Dec 2022 12:13:55 GMT , <htt???/web.archive.org/web/20221218123300/htt????/github.com/advisories/GHSA-763g-fqq7-48wg>; rel= memento ; datetime= Sun, 18 Dec 2022 12:33:00 GMT , <htt???/web.archive.org/web/20221219130510/htt????/github.com/advisories/GHSA-763g-fqq7-48wg>; rel= next memento ; datetime= Mon, 19 Dec 2022 13:05:10 GMT , <htt???/web.archive.org/web/20260610223502/htt????/github.com/advisories/GHSA-763g-fqq7-48wg>; rel= last memento ; datetime= Wed, 10 Jun 2026 22:35:02 GMT
content-security-policy default-src self unsafe-eval unsafe-inline data: blob: archive.org web.archive.org web-static.archive.org wayback-api.archive.org athena.archive.org analytics.archive.org pragma.archivelab.org wwwb-events.archive.org
x-archive-src github.com-20221218-204342/IA-FOC-github.com-20221218121322-00000.warc.gz
server-timing captures_list;dur=0.534521, exclusion.robots;dur=0.059528, exclusion.robots.policy;dur=0.048157, esindex;dur=0.008647, cdx.remote;dur=28.288457, LoadShardBlock;dur=772.982329, PetaboxLoader3.resolve;dur=390.585880, PetaboxLoader3.datanode;dur=494.187700, load_resource;dur=205.748843, nav;dur=0.213334
x-app-server wwwb-app263-dc8
x-ts 200
x-tr 1119
server-timing TR;dur=0,Tw;dur=0,Tc;dur=9
set-cookie wb-p-SERVER=wwwb-app263; path=/
X-location All
X-AS 16276
X-RL 0
X-NA 0
X-Page-Cache MISS
Server-Timing MISS
X-NID OVH SAS
Referrer-Policy no-referrer-when-downgrade
Permissions-Policy interest-cohort=()
X-sd 0
Content-Encoding gzip

Meta Tags

title="maven"
charset="utf-8"
name="request-id" content="AF24:4BA5:2AB188E:3D397D4:639F087C" data-pjax-transient="true"
name="html-safe-nonce" content="fdb58e67e3fdd0eb4442181d78058db7f6cbc34ef22a677a8f45ac7028b05e2a" data-pjax-transient="true"
name="visitor-payload" content="eyJyZWZlcnJlciI6Imh0dHBzOi8vZ2l0aHViLmNvbS9mZWF0dXJlcy9zZWN1cml0eSIsInJlcXVlc3RfaWQiOiJBRjI0OjRCQTU6MkFCMTg4RTozRDM5N0Q0OjYzOUYwODdDIiwidmlzaXRvcl9pZCI6IjQ4MTU1Njg1ODE0OTYzNDE0NzkiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ==" data-pjax-transient="true"
name="visitor-hmac" content="806d6ebdd88978d37685b7c7baaa56bacbd13fe928e5f664430d5b4a3122da44" data-pjax-transient="true"
name="hovercard-subject-tag" content="advisory:1905" data-turbo-transient
name="github-keyboard-shortcuts" content="" data-turbo-transient="true"
name="selected-link" value="/advisories/GHSA-763g-fqq7-48wg" data-turbo-transient
name="google-site-verification" content="c1kuD-K2HIVF635lypcsWPoD4kilo5-jA_wBFyT4uMY"
name="google-site-verification" content="KT5gs8h0wvaagLKAVWq8bbeNwnZZK1r1XQysX3xurLU"
name="google-site-verification" content="ZzhVyEFwb7w3e0-uOTltm8Jsck2F5StVihD0exw2fsA"
name="google-site-verification" content="GXs5KoUUkNCoaAZn7wPN-t01Pywp9M3sEjnt_3_ZWPc"
name="google-site-verification" content="Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I"
name="octolytics-url" content="htt????/collector.github.com/github/collect"
name="analytics-location" content="/advisories/<id>" data-turbo-transient="true"
name="user-login" content=""
name="viewport" content="width=device-width"
name="description" content="GitHub is where people build software. More than 94 million people use GitHub to discover, fork, and contribute to over 330 million projects."
property="fb:app_id" content="1401488693436528"
name="apple-itunes-app" content="app-id=1477376905"
name="twitter:image:src" content="htt????/github.githubassets.com/images/modules/site/social-cards/advisory-database-show.png"
name="twitter:site" content="@github"
name="twitter:card" content="summary"
name="twitter:title" content="CVE-2019-10782 - GitHub Advisory Database"
name="twitter:description" content="XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))"
property="og:image" content="htt???/web.archive.org/web/20221218123300im_/htt????/github.githubassets.com/images/modules/site/social-cards/advisory-database-show.png"
property="og:image:alt" content="XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))"
property="og:site_name" content="GitHub"
property="og:type" content="object"
property="og:title" content="CVE-2019-10782 - GitHub Advisory Database"
property="og:url" content="htt???/web.archive.org/web/20221218123300/htt????/github.com/advisories/GHSA-763g-fqq7-48wg"
property="og:description" content="XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))"
name="hostname" content="github.com"
name="expected-hostname" content="github.com"
name="enabled-features" content="TURBO_EXPERIMENT_RISKY,IMAGE_METRIC_TRACKING,GEOJSON_AZURE_MAPS"
http-equiv="x-pjax-version" content="aa3548fad9d5d363f4ac20999e5a8f0d9edcefb114252f3ea134132878a4cbe0" data-turbo-track="reload"
http-equiv="x-pjax-csp-version" content="40aca5a152a13213a876f7628c466cd600db12fb858cdddccc3f1cc387eb7dad" data-turbo-track="reload"
http-equiv="x-pjax-css-version" content="01292ea9440dd5e730c0f067b68a28b2df4549715b848e1911a3ad0dfb8f5883" data-turbo-track="reload"
http-equiv="x-pjax-js-version" content="47dbc27fc6b2358bab3457cbb98ba36b6ae409a34bbcf47c0432a7a4266dc87a" data-turbo-track="reload"
name="turbo-cache-control" content="no-preview" data-turbo-transient=""
name="turbo-body-classes" content="logged-out env-production page-responsive"
name="browser-stats-url" content="htt????/api.github.com/_private/browser/stats"
name="browser-errors-url" content="htt????/api.github.com/_private/browser/errors"
name="browser-optimizely-client-errors-url" content="htt????/api.github.com/_private/browser/optimizely_client/errors"
name="theme-color" content="#1e2327"
name="color-scheme" content="light dark"

Load Info

page size27946
load time (s)2.896719
redirect count1
speed download9649
server IP 207.241.237.3
* all occurrences of the string "http://" have been changed to "htt???/"