CVE-2019-9658

MEDIUM

checkstyle < 8.18 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

Checkstyle before 8.18 loads external DTDs by default.

References (14)

Core 14
Core References
Third Party Advisory x_refsource_misc
https://github.com/checkstyle/checkstyle/pull/6476
Third Party Advisory x_refsource_misc
https://github.com/checkstyle/checkstyle/issues/6474
Third Party Advisory x_refsource_misc
https://github.com/checkstyle/checkstyle/issues/6478
Release Notes, Vendor Advisory x_refsource_misc
https://checkstyle.org/releasenotes.html#Release_8.18
Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/04/msg00029.html

Scores

CVSS v3 5.3
EPSS 0.0368
EPSS Percentile 88.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-611
Status published
Products (5)
checkstyle/checkstyle < 8.18
com.puppycrawl.tools/checkstyle 0 - 8.18Maven
debian/debian_linux 8.0
fedoraproject/fedora 28
fedoraproject/fedora 29
Published Mar 11, 2019
Tracked Since Feb 18, 2026