Loading
Generated remediation guidance and an executive summary. No account required.
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Use CWE-611, Dom4j Project vendor hub and Dom4j product page to widen CVE-2020-10683 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-1000632 for nearby disclosures in the same product family.