Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/github/bonigarcia/wdm/WebDriverManager.java. This issue affects webdrivermanager: from 1.0.0 before 6.0.2.
History

Wed, 14 May 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 May 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/github/bonigarcia/wdm/WebDriverManager.java. This issue affects webdrivermanager: from 1.0.0 before 6.0.2.
Title XML External Entity (XXE) injection vulnerability in WebDriverManager
Weaknesses CWE-611
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GovTech CSG

Published: 2025-05-14T18:09:26.105Z

Updated: 2025-05-14T20:49:57.890Z

Reserved: 2025-05-13T02:36:29.519Z

Link: CVE-2025-4641

cve-icon Vulnrichment

Updated: 2025-05-14T20:49:55.420Z

cve-icon NVD

Status : Received

Published: 2025-05-14T19:15:53.683

Modified: 2025-05-14T19:15:53.683

Link: CVE-2025-4641

cve-icon Redhat

No data.