XML External Entity Vulnerability in JabRef by JabRef Team
CVE-2018-1000652
10CRITICAL
What is CVE-2018-1000652?
JabRef versions up to 4.3.1 are susceptible to an XML External Entity (XXE) vulnerability in the MsBibImporter XML Parser. This vulnerability may allow attackers to craft specific MsBib files to facilitate the disclosure of confidential information, lead to denial of service, and execute server-side request forgery or port scanning. Users are encouraged to upgrade to the patched versions following commit 89f855d to mitigate these security risks.
