CVE-2022-0839
9.8CRITICALImproper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.
Published: 3/4/2022Updated: 11/3/2025
Description
Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.
AI AnalysisPowered by AI
Affected Products
liquibaseliquibase
oraclesqlcl
19c
References
- https://github.com/liquibase/liquibase/commit/33d9d925082097fb1a3d2fc8e44423d964cd9381Patch
- https://huntr.dev/bounties/f1ae5779-b406-4594-a8a3-d089c68d6e70ExploitPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
- http://seclists.org/fulldisclosure/2025/Apr/14
- https://github.com/liquibase/liquibase/commit/33d9d925082097fb1a3d2fc8e44423d964cd9381Patch
- https://huntr.dev/bounties/f1ae5779-b406-4594-a8a3-d089c68d6e70ExploitPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory