CVE-2019-9658
published 2019-03-11CVE-2019-9658: Checkstyle before 8.18 loads external DTDs by default.
PriorityP430medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
3.68%
88.6th percentile
Checkstyle before 8.18 loads external DTDs by default.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| checkstyle | checkstyle | < 8.18 | 8.18 |
| checkstyle | checkstyle | < 8.29 | 8.29 |
| checkstyle | checkstyle | >= 0 < 8.26-1 | 8.26-1 |
| checkstyle | checkstyle | >= 0 < 8.29-1 | 8.29-1 |
| checkstyle | checkstyle | >= 0 < 8.26-1 | 8.26-1 |
| checkstyle | checkstyle | >= 0 < 8.29-1 | 8.29-1 |
| checkstyle | checkstyle | >= 0 < 8.26-1 | 8.26-1 |
| checkstyle | checkstyle | >= 0 < 8.29-1 | 8.29-1 |
| checkstyle | checkstyle | >= 0 < 8.26-1 | 8.26-1 |
| checkstyle | checkstyle | >= 0 < 8.29-1 | 8.29-1 |
| debian | checkstyle | < checkstyle 8.26-1 (bookworm) | checkstyle 8.26-1 (bookworm) |
| debian | checkstyle | < checkstyle 8.29-1 (bookworm) | checkstyle 8.29-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
ghsa5.3MEDIUM
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))
osv·2020-01-31·CVSS 5.3
CVE-2019-10782 [MEDIUM] XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))
XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))
Due to an incomplete fix for [CVE-2019-9658](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9658), checkstyle was still vulnerable to XML External Entity (XXE) Processing.
### Impact
#### User: Build Maintainers
This vulnerability probably doesn't impact Maven/Gradle users as, in most cases, these builds are processing files that are trusted, or pre-vetted by a pull request reviewer before being run on internal CI infrastructure.
#### User: Static Analysis as a Service
If you operate a site/service that parses "untrusted" Checkstyle XML configuration files, you are vulnerable to this and should patch.
Note from the discoverer of the original CVE-2019-9658:
> While looking a
GHSA
XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))
ghsa·2020-01-31·CVSS 5.3
CVE-2019-10782 [MEDIUM] CWE-611 XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))
XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))
Due to an incomplete fix for [CVE-2019-9658](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9658), checkstyle was still vulnerable to XML External Entity (XXE) Processing.
### Impact
#### User: Build Maintainers
This vulnerability probably doesn't impact Maven/Gradle users as, in most cases, these builds are processing files that are trusted, or pre-vetted by a pull request reviewer before being run on internal CI infrastructure.
#### User: Static Analysis as a Service
If you operate a site/service that parses "untrusted" Checkstyle XML configuration files, you are vulnerable to this and should patch.
Note from the discoverer of the original CVE-2019-9658:
> While looking a
OSV
CVE-2019-10782: All versions of com
osv·2020-01-30·CVSS 5.3
CVE-2019-10782 [MEDIUM] CVE-2019-10782: All versions of com
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
OSV
Moderate severity vulnerability that affects com.puppycrawl.tools:checkstyle
osv·2019-03-14
CVE-2019-9658 [MEDIUM] Moderate severity vulnerability that affects com.puppycrawl.tools:checkstyle
Moderate severity vulnerability that affects com.puppycrawl.tools:checkstyle
Checkstyle prior to 8.18 loads external DTDs by default, which can potentially lead to denial of service attacks or the leaking of confidential information.
GHSA
Moderate severity vulnerability that affects com.puppycrawl.tools:checkstyle
ghsa·2019-03-14
CVE-2019-9658 [MEDIUM] CWE-611 Moderate severity vulnerability that affects com.puppycrawl.tools:checkstyle
Moderate severity vulnerability that affects com.puppycrawl.tools:checkstyle
Checkstyle prior to 8.18 loads external DTDs by default, which can potentially lead to denial of service attacks or the leaking of confidential information.
OSV
CVE-2019-9658: Checkstyle before 8
osv·2019-03-11·CVSS 5.3
CVE-2019-9658 [MEDIUM] CVE-2019-9658: Checkstyle before 8
Checkstyle before 8.18 loads external DTDs by default.
Red Hat
checkstyle: XML External Entity Injection due to an incomplete fix for CVE-2019-9658
vendor_redhat·2020-01-27·CVSS 5.3
CVE-2019-10782 [MEDIUM] CWE-611 checkstyle: XML External Entity Injection due to an incomplete fix for CVE-2019-9658
checkstyle: XML External Entity Injection due to an incomplete fix for CVE-2019-9658
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
Statement: No Red Hat products use the vulnerable code affected by this flaw. However, Red Hat Fuse 7 does provide it in its offline maven repository, and as such is affected at a low impact. This may be resolved in a future release.
Package: checkstyle (Red Hat Fuse 7) - Fix deferred
Debian
CVE-2019-9658: checkstyle - Checkstyle before 8.18 loads external DTDs by default.
vendor_debian·2019·CVSS 5.3
CVE-2019-9658 [MEDIUM] CVE-2019-9658: checkstyle - Checkstyle before 8.18 loads external DTDs by default.
Checkstyle before 8.18 loads external DTDs by default.
Scope: local
bookworm: resolved (fixed in 8.26-1)
bullseye: resolved (fixed in 8.26-1)
forky: resolved (fixed in 8.26-1)
sid: resolved (fixed in 8.26-1)
trixie: resolved (fixed in 8.26-1)
Debian
CVE-2019-10782: checkstyle - All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XM...
vendor_debian·2019·CVSS 5.3
CVE-2019-10782 [MEDIUM] CVE-2019-10782: checkstyle - All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XM...
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
Scope: local
bookworm: resolved (fixed in 8.29-1)
bullseye: resolved (fixed in 8.29-1)
forky: resolved (fixed in 8.29-1)
sid: resolved (fixed in 8.29-1)
trixie: resolved (fixed in 8.29-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10782 checkstyle: XML External Entity Injection due to an incomplete fix for CVE-2019-9658 [fedora-all]
bugzilla·2020-01-31·CVSS 5.3
CVE-2019-10782 [MEDIUM] CVE-2019-10782 checkstyle: XML External Entity Injection due to an incomplete fix for CVE-2019-9658 [fedora-all]
CVE-2019-10782 checkstyle: XML External Entity Injection due to an incomplete fix for CVE-2019-9658 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2019-10782 checkstyle: XML External Entity Injection due to an incomplete fix for CVE-2019-9658
bugzilla·2020-01-31·CVSS 5.3
CVE-2019-10782 [MEDIUM] CVE-2019-10782 checkstyle: XML External Entity Injection due to an incomplete fix for CVE-2019-9658
CVE-2019-10782 checkstyle: XML External Entity Injection due to an incomplete fix for CVE-2019-9658
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
References:
https://snyk.io/vuln/SNYK-JAVA-COMPUPPYCRAWLTOOLS-543266
Discussion:
Created checkstyle tracking bugs for this issue:
Affects: fedora-all [bug 1796859]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
---
Statement:
No Red Hat products use the vulnerable code affected by this flaw. However, Red Hat Fuse 7 does provide it in its o
Bugzilla
CVE-2019-9658 checkstyle: Loads external DTDs by default [fedora-all]
bugzilla·2019-04-01·CVSS 5.3
CVE-2019-9658 [MEDIUM] CVE-2019-9658 checkstyle: Loads external DTDs by default [fedora-all]
CVE-2019-9658 checkstyle: Loads external DTDs by default [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2019-9658 checkstyle: Loads external DTDs by default
bugzilla·2019-04-01·CVSS 5.3
CVE-2019-9658 [MEDIUM] CVE-2019-9658 checkstyle: Loads external DTDs by default
CVE-2019-9658 checkstyle: Loads external DTDs by default
Checkstyle before 8.18 loads external DTDs by default.
Upstream issue:
https://github.com/checkstyle/checkstyle/issues/6474
https://github.com/checkstyle/checkstyle/issues/6478
Upstream patch:
https://github.com/checkstyle/checkstyle/pull/6476
References:
https://checkstyle.org/releasenotes.html#Release_8.18
Discussion:
Created checkstyle tracking bugs for this issue:
Affects: fedora-all [bug 1694858]
---
checkstyle-8.0-4.1.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.
---
checkstyle-8.0-4.1.fc29 has been pushed to the Fedora 29 stable repository. If problems still persist, please make note of it in this bug report.
---
This CVE Bugzilla
https://checkstyle.org/releasenotes.html#Release_8.18https://github.com/checkstyle/checkstyle/issues/6474https://github.com/checkstyle/checkstyle/issues/6478https://github.com/checkstyle/checkstyle/pull/6476https://lists.apache.org/thread.html/6bf8bbbca826e883f09ba40bc0d319350e1d6d4cf4df7c9e399b2699%40%3Ccommits.fluo.apache.org%3Ehttps://lists.apache.org/thread.html/7eea10e7be4c21060cb1e79f6524c6e6559ba833b1465cd2870a56b9%40%3Cserver-dev.james.apache.org%3Ehttps://lists.apache.org/thread.html/994221405e940e148adcfd9cb24ffc6700bed70c7820c55a22559d26%40%3Cnotifications.fluo.apache.org%3Ehttps://lists.apache.org/thread.html/a35a8ccb316d4c2340710f610cba8058e87d5376259b35ef3ed2bf89%40%3Cnotifications.accumulo.apache.org%3Ehttps://lists.apache.org/thread.html/fff26ee7b59360a0264fef4e8ed9454ef652db2c39f2892a9ea1c9cb%40%3Cnotifications.fluo.apache.org%3Ehttps://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679%40%3Ccommits.nifi.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/04/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2BMOPJ2XYE4LB2HM7OMSUBBIYEDUTLWE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEYBAHYAV37WHMOXZYM2ZWF46FHON6YC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VJPT54USMGWT3Y6XVXLDEHKRUY2EI4OE/https://checkstyle.org/releasenotes.html#Release_8.18https://github.com/checkstyle/checkstyle/issues/6474https://github.com/checkstyle/checkstyle/issues/6478https://github.com/checkstyle/checkstyle/pull/6476https://lists.apache.org/thread.html/6bf8bbbca826e883f09ba40bc0d319350e1d6d4cf4df7c9e399b2699%40%3Ccommits.fluo.apache.org%3Ehttps://lists.apache.org/thread.html/7eea10e7be4c21060cb1e79f6524c6e6559ba833b1465cd2870a56b9%40%3Cserver-dev.james.apache.org%3Ehttps://lists.apache.org/thread.html/994221405e940e148adcfd9cb24ffc6700bed70c7820c55a22559d26%40%3Cnotifications.fluo.apache.org%3Ehttps://lists.apache.org/thread.html/a35a8ccb316d4c2340710f610cba8058e87d5376259b35ef3ed2bf89%40%3Cnotifications.accumulo.apache.org%3Ehttps://lists.apache.org/thread.html/fff26ee7b59360a0264fef4e8ed9454ef652db2c39f2892a9ea1c9cb%40%3Cnotifications.fluo.apache.org%3Ehttps://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679%40%3Ccommits.nifi.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/04/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2BMOPJ2XYE4LB2HM7OMSUBBIYEDUTLWE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEYBAHYAV37WHMOXZYM2ZWF46FHON6YC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VJPT54USMGWT3Y6XVXLDEHKRUY2EI4OE/
2019-03-11
Published