CVE Vulnerabilities

CVE-2020-13692

Improper Restriction of XML External Entity Reference

Published: Jun 04, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.7
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.7 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

NameVendorStart VersionEnd Version
Postgresql_jdbc_driverPostgresql*42.2.13 (excluding)
Red Hat AMQ Online 1.5.2 GARedHatjdbc-postgresql*
Red Hat build of Quarkus 1.3.4 SP1RedHatquarkus-jdbc-postgresql*
Red Hat build of Quarkus 1.3.4 SP1RedHatquarkus-jdbc-postgresql-deployment*
Red Hat Decision Manager 7RedHatjdbc-postgresql*
Red Hat Enterprise Linux 6RedHatpostgresql-jdbc-0:8.4.704-4.el6_10*
Red Hat Enterprise Linux 7RedHatpostgresql-jdbc-0:9.2.1002-8.el7_8*
Red Hat Enterprise Linux 8RedHatpostgresql-jdbc-0:42.2.3-3.el8_2*
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsRedHatpostgresql-jdbc-0:42.2.3-3.el8_0*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatpostgresql-jdbc-0:42.2.3-3.el8_1*
Red Hat Fuse 7.8.0RedHatjdbc-postgresql*
Red Hat Integration - Camel K - Tech-Preview 2RedHatjdbc-postgresql*
Red Hat Integration Debezium 1.1.3RedHatjdbc-postgresql*
Red Hat Process Automation 7RedHatjdbc-postgresql*
LibpgjavaUbuntubionic*
LibpgjavaUbuntueoan*
LibpgjavaUbuntuesm-apps/bionic*
LibpgjavaUbuntuesm-apps/focal*
LibpgjavaUbuntufocal*
LibpgjavaUbuntutrusty*
LibpgjavaUbuntuupstream*
LibpgjavaUbuntuxenial*

Potential Mitigations

References