CVE-2019-9658 describes a vulnerability in Checkstyle versions prior to 8.18, where the software insecurely loads external DTDs by default, affecting various Checkstyle distributions across Debian and Fedora. This medium-severity vulnerability (CVSS 5.3) allows for an XML External Entity (XXE) injection, potentially leading to information disclosure (CWE-611) with low impact on confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.18CPE matchmatch criteria | cpe:2.3:a:checkstyle:checkstyle:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
28CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.