-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability is explicitly tied to XML external entity processing in XfaFile.java. While the exact commit diff is unavailable, XXE vulnerabilities typically stem from insecure XML parser configurations (e.g., failing to set FEATURE_SECURE_PROCESSING or disable DTDs). The class XfaFile is explicitly named in the advisory, and its role in processing XFA (XML-based PDF forms) strongly implies XML parsing logic. The high confidence stems from the direct correlation between the CWE, the file location, and the vulnerability description.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.itextpdf:itext-rups | maven | <= 7.0.1 |
Ongoing coverage of React2Shell