{"id":"CVE-2020-10683","aliases":["GHSA-hwj3-m3p6-hj38"],"url":"https://o3.security/vulnerability/CVE-2020-10683","summary":"dom4j allows External Entities by default which might enable XXE attacks","details":"dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.","published":"2020-05-01T19:15:12.927Z","modified":"2026-08-27T19:33:48.786302Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.dom4j:dom4j","fixedVersion":"2.0.3"},{"ecosystem":"Maven","name":"org.dom4j:dom4j","fixedVersion":"2.1.3"},{"ecosystem":"Maven","name":"dom4j:dom4j","fixedVersion":null}],"fix":{"url":"https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658","label":"dom4j/dom4j@a822852"},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8%40%3Cdev.velocity.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32%40%3Cdev.velocity.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3E"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html"},{"type":"ADVISORY","url":"https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html"},{"type":"ADVISORY","url":"https://github.com/dom4j/dom4j/issues/87"},{"type":"ADVISORY","url":"https://github.com/dom4j/dom4j/releases/tag/version-2.1.3"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20200518-0002/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4575-1/"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1694235"},{"type":"FIX","url":"https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658"},{"type":"FIX","url":"https://github.com/dom4j/dom4j/commits/version-2.0.3"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T19:33:48.786302Z"}}