veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability

Description

Impact

Executing policy checks using custom schematron files via the CLI invokes an XSL transformation that may theoretically lead to a remote code execution (RCE) vulnerability.

Patches

We are currently working on a patch that will be released when ready.

Workarounds

This doesn't affect the standard validation and policy checks functionality, veraPDF's common use cases. Most veraPDF users don't insert any custom XSLT code into policy profiles, which are based on Schematron syntax rather than direct XSL transforms. For users who do, only load custom policy files from sources you trust.

References

Original issue: #1488

Basic information

Type
reviewed
Severity
low
Advisory on GitHub
Open advisory ↗
Repository advisory
Open repository advisory ↗
Source code
Browse source ↗
Published (advisory)
2024-12-02 17:15:24 UTC
Updated
2026-05-14 20:44:46 UTC
GitHub reviewed
2024-12-02 17:15:24 UTC
NVD published
2024-11-29

EPSS Score

Score Percentile
12.49% 93.95%

CVSS Scores

Base score Version Severity Vector
2.3 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network.
Attack complexity (AC:L)
Exploitation conditions are straightforward and stable.
Attack requirements (AT:P)
Additional preconditions must be present for exploitation.
Privileges required (PR:N)
No privileges are required.
User interaction (UI:P)
A user has to participate (for example click/open/approve).
Vulnerable system confidentiality impact (VC:L)
Limited confidentiality impact on the vulnerable system.
Vulnerable system integrity impact (VI:L)
Limited integrity impact on the vulnerable system.
Vulnerable system availability impact (VA:N)
No availability impact on the vulnerable system.
Subsequent system confidentiality impact (SC:N)
No confidentiality impact on subsequent systems.
Subsequent system integrity impact (SI:N)
No integrity impact on subsequent systems.
Subsequent system availability impact (SA:N)
No availability impact on subsequent systems.

Identifiers

CWEs

CWE id Name
CWE-611 Improper Restriction of XML External Entity Reference

Affected packages (9)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
maven org.verapdf:core <= 1.26.1 1.26.2
maven org.verapdf:core-jakarta <= 1.26.1 1.26.2
maven org.verapdf:core-arlington <= 1.26.1 1.26.2
maven org.verapdf:verapdf-library-jakarta <= 1.26.1 1.26.2
maven org.verapdf:verapdf-library-arlington <= 1.26.1 1.26.2
maven org.verapdf:verapdf-library <= 1.26.1 1.26.2
maven org.verapdf:library <= 1.26.1 1.26.2
maven org.verapdf:library-jakarta <= 1.26.1 1.26.2
maven org.verapdf:library-arlington <= 1.26.1 1.26.2

References

cvelogic Threat Intelligence