Vulnerability Intelligence Report
CVE-2017-12620
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:3.02%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Apache Software Foundation | Apache OpenNLP | 1.5.0 to 1.5.3 (affected), 1.6.0 (affected), 1.7.0 to 1.7.2 (affected), 1.8.0 to 1.8.1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
3.016%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Apache Software Foundation · Vendor · USA |
| Reserved | 2017-08-07T00:00:00 |
| Published | 2017-10-02T14:00:00 |
| Patch Date | 2017-10-02 |
| Last Updated | 2024-09-16T19:15:51 |
Community Chatter & Buzz