diffplug/spotless

diffplug/spotless

Releases545
Frequency1 week 10 hours
Last Release
Stars5.5K
Keep your code spotless

CVE History

CVEPublishedCVSS v3CVSS v2
5.1 MEDIUM

In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file.