poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem
Published Oct 23, 2019
5.5
MEDIUMCVSS 3.1
EPSS 1.00%
Description
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Affected products
- Vendor n/a Product Apache POI Defaultn/a
- Version Apache POI up to 4.1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Apache POI | n/a |
|
Configuration 2
- 12.5.0.3
- 13.1.0.1
- 13.2.0.1
- 13.3.0.1
- 2.7.0
- 2.8.0
- 2.7.0
- 2.8.0
- 14.0.0
- 14.1.0
- 2.4.0
- 2.4.1
- 2.5.0
- 2.6.0
- 2.6.1
- 2.6.2
- 2.7.0
- 2.7.1
- 2.9.0
- 1.6
- n/a
- n/a
- 3.2.0
- 12.1.0.5
- 13.3.0.0
- 13.4.0.0
- 12.1.3.0.0
- ≥ 8.0.6 · ≤ 8.0.9
- 8.0.6
- 8.0.8
- 12.0.0
- 12.1.0
- 11.1.2.4
- 17.1
- 17.2
- 17.3
- 11.0.2
- 11.1.0
- 11.2.0
- 10.2.0
- 10.2.4
- 11.0.2
- 11.1.0
- 11.2.0
- 12.2.1.4.0
- 8.57
- 8.58
- 8.59
- 17.12.6
- 18.8.8.1
- ≥ 17.7 · ≤ 17.12
- 16.1
- 16.2
- 18.8
- 19.12
- 14.0
- 15.0
- 16.0
- 15.0.3
- 16.0.3
- 12.2.1.3.0
- 12.2.1.4.0
- 12.2.1.3.0
- 12.2.1.4.0
No data.
Red Hat Fuse 7.10
poi
Fixed · RHSA-2021:5134
Red Hat BPM Suite 6
poi
Out of support scope
Red Hat Decision Manager 7
poi
Fix deferred
Red Hat JBoss BRMS 5
poi
Out of support scope
Red Hat JBoss Data Virtualization 6
poi
Out of support scope
Red Hat JBoss Fuse 6
poi
Out of support scope
Red Hat JBoss Fuse Service Works 6
poi
Out of support scope
Red Hat Process Automation 7
poi
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.10 | poi | Fixed | RHSA-2021:5134 |
| Red Hat BPM Suite 6 | poi | Out of support scope | n/a |
| Red Hat Decision Manager 7 | poi | Fix deferred | n/a |
| Red Hat JBoss BRMS 5 | poi | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | poi | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | poi | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | poi | Out of support scope | n/a |
| Red Hat Process Automation 7 | poi | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
The vulnerability is in the XSSFExportToXml util; avoid usage of this tool to mitigate the vulnerability.
References (23)
- https://access.redhat.com/security/cve/CVE-2019-12415 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1802531 Issue Tracking
- https://github.com/advisories/GHSA-9jwc-q6j3-8g9g Advisory
- https://lists.apache.org/thread.html/13a54b6a03369cfb418a699180ffb83bd727320b6ddfec198b9b728e%40%3Cannounce.apache.org%3E x_refsource_MISC
- https://lists.apache.org/thread.html/13a54b6a03369cfb418a699180ffb83bd727320b6ddfec198b9b728e@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/2ac0327748de0c2b3c1c012481b79936797c711724e0b7da83cf564c%40%3Cuser.tika.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/2ac0327748de0c2b3c1c012481b79936797c711724e0b7da83cf564c@%3Cuser.tika.apache.org%3E
- https://lists.apache.org/thread.html/895164e03a3c327449069e2fd6ced0367561878b3ae6a8ec740c2007%40%3Cuser.tika.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/895164e03a3c327449069e2fd6ced0367561878b3ae6a8ec740c2007@%3Cuser.tika.apache.org%3E
- https://lists.apache.org/thread.html/d88b8823867033514d7ec05d66f88c70dc207604d3dcbd44fd88464c%40%3Cuser.tika.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/d88b8823867033514d7ec05d66f88c70dc207604d3dcbd44fd88464c@%3Cuser.tika.apache.org%3E
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2019-12415
- https://www.cve.org/CVERecord?id=CVE-2019-12415
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCThird Party Advisory
Change history (0)
No recorded changes yet.