CVE-2024-28168: Apache XML Graphics FOP: XML External Entity (XXE) Processing
Apache XML Graphics FOP is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. By sending specially crafted XML data, a remote attacker could exploit this vulnerability to obtain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28168?
CVE-2024-28168 is classified as a critical severity vulnerability due to its potential for unauthorized access through XML External Entity injection.
How do I fix CVE-2024-28168?
To fix CVE-2024-28168, users should upgrade Apache XML Graphics FOP to version 2.10 or later.
Which versions of Apache XML Graphics FOP are affected by CVE-2024-28168?
CVE-2024-28168 affects Apache XML Graphics FOP versions up to and including 2.9.
What type of vulnerability is CVE-2024-28168?
CVE-2024-28168 is an Improper Restriction of XML External Entity Reference (XXE) vulnerability.
Who is impacted by CVE-2024-28168?
Any users and applications utilizing Apache XML Graphics FOP version 2.9 or earlier are impacted by CVE-2024-28168.