CVE-2019-12415: Improper Restriction of XML External Entity Reference
(updated )
In Apache POI, when using the tool XSSFExportToXml
to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
References
Detect and mitigate CVE-2019-12415 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →