« Volver al listado

CVE-2025-68280

Estado: AnalizadaMedia (6.5)—

Improper Restriction of XML External Entity Reference vulnerability in Apache SIS.

It is possible to write XML files in such a way that, when parsed by Apache SIS, an XML file reveals to the attacker the content of a local file on the server running Apache SIS. This vulnerability impacts the following SIS services:

This issue affects Apache SIS from versions 0.4 through 1.5 inclusive. Users are recommended to upgrade to version 1.6, which will fix the issue. In the meantime, the security vulnerability can be avoided by launching Java with the javax.xml.accessExternalDTD system property sets to a comma-separated list of authorized protocols. For example:

Leer descripción completaMostrar menos

java -Djavax.xml.accessExternalDTD="" ...

Detalles técnicos trazas, registros y código del informe original
  *  Reading of GeoTIFF files having the GEO_METADATA tag defined by the Defense Geospatial Information Working Group (DGIWG).

  *  Parsing of ISO 19115 metadata in XML format.

  *  Parsing of Coordinate Reference Systems defined in the GML format.

  *  Parsing of files in GPS Exchange Format (GPX).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-68280",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-68280",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-05T14:54:32.089019Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache SIS",
          "versions": [
            {
              "status": "affected",
              "version": "0.4",
              "versionType": "semver",
              "lessThanOrEqual": "1.5"
            }
          ],
          "packageName": "org.apache.sis.core:sis-metadata",
          "collectionURL": "https://repo.maven.apache.org/maven2/org/apache/sis/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-01-05T14:15:53.490",
  "references": [
    {
      "url": "https://lists.apache.org/thread/s4ggy3zbtrrn93glgo2vn52lgcxk4bp4",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/01/05/11",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/01/05/7",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-611"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Restriction of XML External Entity Reference vulnerability in Apache SIS.\n\n\n\nIt is possible to write XML files in such a way that, when parsed by Apache SIS, an XML file reveals to the attacker the content of a local file on the server running Apache SIS. This vulnerability impacts the following SIS services:\n\n\n\n\n  *  Reading of GeoTIFF files having the GEO_METADATA tag defined by the Defense Geospatial Information Working Group (DGIWG).\n\n  *  Parsing of ISO 19115 metadata in XML format.\n\n  *  Parsing of Coordinate Reference Systems defined in the GML format.\n\n  *  Parsing of files in GPS Exchange Format (GPX).\n\n\n\n\n\nThis issue affects Apache SIS from versions 0.4 through 1.5 inclusive. Users are recommended to upgrade to version 1.6, which will fix the issue. In the meantime, the security vulnerability can be avoided by launching Java with the javax.xml.accessExternalDTD system property sets to a comma-separated list of authorized protocols. For example:\n\n\n\njava -Djavax.xml.accessExternalDTD=\"\" ..."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de restricción inadecuada de referencia a entidad externa XML en Apache SIS.\n\nEs posible escribir archivos XML de tal manera que, cuando son analizados por Apache SIS, un archivo XML revele al atacante el contenido de un archivo local en el servidor que ejecuta Apache SIS. Esta vulnerabilidad afecta a los siguientes servicios de SIS:\n\n  *  Lectura de archivos GeoTIFF que tienen la etiqueta GEO_METADATA definida por el Grupo de Trabajo de Información Geoespacial de Defensa (DGIWG).\n  *  Análisis de metadatos ISO 19115 en formato XML.\n  *  Análisis de Sistemas de Referencia de Coordenadas definidos en formato GML.\n  *  Análisis de archivos en formato de Intercambio GPS (GPX).\n\nEste problema afecta a Apache SIS desde las versiones 0.4 hasta la 1.5, ambas inclusive. Se recomienda a los usuarios actualizar a la versión 1.6, que solucionará el problema. Mientras tanto, la vulnerabilidad de seguridad puede evitarse iniciando Java con la propiedad de sistema javax.xml.accessExternalDTD establecida a una lista de protocolos autorizados separada por comas. Por ejemplo:\n\njava -Djavax.xml.accessExternalDTD=“” ..."
    }
  ],
  "lastModified": "2026-09-30T23:10:00.237",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:spatial_information_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2300667C-6062-4598-AB98-245C74796E1E",
              "versionEndIncluding": "1.5",
              "versionStartIncluding": "0.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}