CVE Published: 24/03/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache POI Status : PUBLISHED
CVE-2017-5644 Description
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.