CVE advisoryCRITICAL
CVE-2020-10683
dom4j XXE Vulnerability Enabling External Entity Attacks
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A vulnerability in the dom4j Java library allows external DTDs and entities by default, potentially enabling XML External Entity (XXE) attacks. This could lead to unauthorized access or modification of system data if reachable. While external documentation shows how to enable safer behavior, applications using vulnerab