CVE-2024-28168: Apache XML Graphics FOP: XML External Entity (XXE) Processing
Apache XML Graphics FOP is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. By sending specially crafted XML data, a remote attacker could exploit this vulnerability to obtain sensitive information.
Other sources
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP.
This issue affects Apache XML Graphics FOP: 2.9.
Users are recommended to upgrade to version 2.10, which fixes the issue.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28168?
CVE-2024-28168 is classified as a critical severity vulnerability due to its potential for unauthorized access through XML External Entity injection.
How do I fix CVE-2024-28168?
To fix CVE-2024-28168, users should upgrade Apache XML Graphics FOP to version 2.10 or later.
Which versions of Apache XML Graphics FOP are affected by CVE-2024-28168?
CVE-2024-28168 affects Apache XML Graphics FOP versions up to and including 2.9.
What type of vulnerability is CVE-2024-28168?
CVE-2024-28168 is an Improper Restriction of XML External Entity Reference (XXE) vulnerability.
Who is impacted by CVE-2024-28168?
Any users and applications utilizing Apache XML Graphics FOP version 2.9 or earlier are impacted by CVE-2024-28168.