Fedora Account System
Red Hat Associate
Red Hat Customer
Apache POI's XLSX2CSV example uses Java's XML components to parse OpenXML files. Applications and users that use XLSX2CSV and accept such files from end-users are vulnerable to XML External Entity (XXE) attacks, which allow remote attackers to bypass security restrictions and read arbitrary files via a crafted OpenXML document that provides an XML external entity declaration in conjunction with an entity reference. Affected versions: POI 3.5-3.13 Public via: http://seclists.org/bugtraq/2016/Jul/106
Created apache-poi tracking bugs for this issue: Affects: fedora-all [bug 1359664]