{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "Possible local text file exfiltration by XML External entity injection",
    "tracking": {
      "current_release_date": "2026-07-24T19:31:25+00:00",
      "generator": {
        "date": "2026-07-24T19:31:25+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.1.0"
        }
      },
      "id": "CVE-2023-42445",
      "initial_release_date": "2023-10-06T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-07-24T19:31:25+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Software Collections",
            "product": {
              "name": "Red Hat Software Collections",
              "product_id": "rhscl-3",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhel_software_collections:3"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rh-maven36-byte-buddy",
            "product": {
              "name": "rh-maven36-byte-buddy",
              "product_id": "rh-maven36-byte-buddy",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rh-maven36-byte-buddy"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rh-maven36-byte-buddy-agent",
            "product": {
              "name": "rh-maven36-byte-buddy-agent",
              "product_id": "rh-maven36-byte-buddy-agent",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rh-maven36-byte-buddy-agent"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rh-maven36-byte-buddy-javadoc",
            "product": {
              "name": "rh-maven36-byte-buddy-javadoc",
              "product_id": "rh-maven36-byte-buddy-javadoc",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rh-maven36-byte-buddy-javadoc"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rh-maven36-byte-buddy-maven-plugin",
            "product": {
              "name": "rh-maven36-byte-buddy-maven-plugin",
              "product_id": "rh-maven36-byte-buddy-maven-plugin",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rh-maven36-byte-buddy-maven-plugin"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rh-maven36-byte-buddy-parent",
            "product": {
              "name": "rh-maven36-byte-buddy-parent",
              "product_id": "rh-maven36-byte-buddy-parent",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rh-maven36-byte-buddy-parent"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rh-maven36-byte-buddy",
            "product": {
              "name": "rh-maven36-byte-buddy",
              "product_id": "rh-maven36-byte-buddy.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rh-maven36-byte-buddy?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-maven36-byte-buddy as a component of Red Hat Software Collections",
          "product_id": "rhscl-3:rh-maven36-byte-buddy"
        },
        "product_reference": "rh-maven36-byte-buddy",
        "relates_to_product_reference": "rhscl-3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-maven36-byte-buddy-agent as a component of Red Hat Software Collections",
          "product_id": "rhscl-3:rh-maven36-byte-buddy-agent"
        },
        "product_reference": "rh-maven36-byte-buddy-agent",
        "relates_to_product_reference": "rhscl-3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-maven36-byte-buddy-javadoc as a component of Red Hat Software Collections",
          "product_id": "rhscl-3:rh-maven36-byte-buddy-javadoc"
        },
        "product_reference": "rh-maven36-byte-buddy-javadoc",
        "relates_to_product_reference": "rhscl-3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-maven36-byte-buddy-maven-plugin as a component of Red Hat Software Collections",
          "product_id": "rhscl-3:rh-maven36-byte-buddy-maven-plugin"
        },
        "product_reference": "rh-maven36-byte-buddy-maven-plugin",
        "relates_to_product_reference": "rhscl-3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-maven36-byte-buddy-parent as a component of Red Hat Software Collections",
          "product_id": "rhscl-3:rh-maven36-byte-buddy-parent"
        },
        "product_reference": "rh-maven36-byte-buddy-parent",
        "relates_to_product_reference": "rhscl-3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-maven36-byte-buddy.src as a component of Red Hat Software Collections",
          "product_id": "rhscl-3:rh-maven36-byte-buddy.src"
        },
        "product_reference": "rh-maven36-byte-buddy.src",
        "relates_to_product_reference": "rhscl-3"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-42445",
      "cwe": {
        "id": "CWE-611",
        "name": "Improper Restriction of XML External Entity Reference"
      },
      "discovery_date": "2023-10-06T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhscl-3:rh-maven36-byte-buddy-javadoc"
          ]
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Gradle. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), parsing XML can lead to the exfiltration of local text files to a remote server. In most cases, Gradle parses XML files it generated, or that were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "rhscl-3:rh-maven36-byte-buddy",
          "rhscl-3:rh-maven36-byte-buddy-agent",
          "rhscl-3:rh-maven36-byte-buddy-maven-plugin",
          "rhscl-3:rh-maven36-byte-buddy-parent",
          "rhscl-3:rh-maven36-byte-buddy.src"
        ],
        "known_not_affected": [
          "rhscl-3:rh-maven36-byte-buddy-javadoc"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2023-42445"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42445"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-42445"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "rhscl-3:rh-maven36-byte-buddy",
            "rhscl-3:rh-maven36-byte-buddy-agent",
            "rhscl-3:rh-maven36-byte-buddy-maven-plugin",
            "rhscl-3:rh-maven36-byte-buddy-parent",
            "rhscl-3:rh-maven36-byte-buddy.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM"
          },
          "products": [
            "rhscl-3:rh-maven36-byte-buddy",
            "rhscl-3:rh-maven36-byte-buddy-agent",
            "rhscl-3:rh-maven36-byte-buddy-javadoc",
            "rhscl-3:rh-maven36-byte-buddy-maven-plugin",
            "rhscl-3:rh-maven36-byte-buddy-parent",
            "rhscl-3:rh-maven36-byte-buddy.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "rhscl-3:rh-maven36-byte-buddy",
            "rhscl-3:rh-maven36-byte-buddy-agent",
            "rhscl-3:rh-maven36-byte-buddy-javadoc",
            "rhscl-3:rh-maven36-byte-buddy-maven-plugin",
            "rhscl-3:rh-maven36-byte-buddy-parent",
            "rhscl-3:rh-maven36-byte-buddy.src"
          ]
        }
      ],
      "title": "Possible local text file exfiltration by XML External entity injection"
    }
  ]
}