LPS-67683 XXE vulnerability in PDFBox

Description

In Liferay Portal 7.0.1 and earlier, PDFBox does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

Severity

Severity 1

Fixed Version(s)

Publication date: Tue, 23 Aug 2016 07:33:00 +0000