← Back

CVE-2020-14338

nvd nist
Published: Sep 17, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.

Affected (3)

Products: Redhat: Xerces
1 product
Xerces
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Before 2.12.0
Version 2.12.0 sp1
Version 2.12.0 sp2

Timeline

No history available yet.