« Volver al listado

CVE-2017-12620

Estado: ModificadaCrítica (9.8)—

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-12620",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache OpenNLP",
          "versions": [
            {
              "status": "affected",
              "version": "1.5.0 to 1.5.3"
            },
            {
              "status": "affected",
              "version": "1.6.0"
            },
            {
              "status": "affected",
              "version": "1.7.0 to 1.7.2"
            },
            {
              "status": "affected",
              "version": "1.8.0 to 1.8.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-10-03T01:29:01.233",
  "references": [
    {
      "url": "http://opennlp.apache.org/news/cve-2017-12620.html",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://opennlp.apache.org/news/cve-2017-12620.html",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-611"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected."
    },
    {
      "lang": "es",
      "value": "A la hora de cargar modelos o diccionarios que contengan XML, es posible realizar un ataque XEE (XML External Entity). Ya que Apache OpenNLP es una librería, solo afecta a aplicaciones que cargan modelos o diccionarios de orígenes desconocidos. Las versiones afectadas de Apache OpenNLP son de la 1.5.0 a la 1.5.3, la 1.6.0, de la 1.7.0 a la 1.7.2 y de la 1.8.0 a la 1.8.1."
    }
  ],
  "lastModified": "2026-06-17T01:03:38.823",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:opennlp:1.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4CA59EC-7EC1-4076-B65A-D018EF723B2B"
            },
            {
              "criteria": "cpe:2.3:a:apache:opennlp:1.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "005F1448-FB8F-4BDC-951C-57B1374BA21F"
            },
            {
              "criteria": "cpe:2.3:a:apache:opennlp:1.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15A7CFF7-D3FC-43DB-B670-4B7AF57F0FE8"
            },
            {
              "criteria": "cpe:2.3:a:apache:opennlp:1.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D76D779B-A94C-4B11-A236-7F8D7FB829EE"
            },
            {
              "criteria": "cpe:2.3:a:apache:opennlp:1.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30344145-13D3-4A56-87EF-E699E8772A2D"
            },
            {
              "criteria": "cpe:2.3:a:apache:opennlp:1.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9358E641-684D-4490-A265-171B5E53A4D7"
            },
            {
              "criteria": "cpe:2.3:a:apache:opennlp:1.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3B33045-2231-4401-80D8-6CD160D3277A"
            },
            {
              "criteria": "cpe:2.3:a:apache:opennlp:1.7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "534308F6-389B-4FC9-94EB-44F6309B7E24"
            },
            {
              "criteria": "cpe:2.3:a:apache:opennlp:1.8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C791176-008B-4C0D-8BFB-E8D52CD05947"
            },
            {
              "criteria": "cpe:2.3:a:apache:opennlp:1.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39263FB2-4AE2-4F8A-A975-1F64FFBE773A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}