docx4j 是一个开源的 Java 库,用于创建、编辑和保存 OpenXML 包(包括 DOCX、PPTX 和 XLSX 文件)。在 11.5.14 版本之前, 及其相关辅助类在递归追踪 WordprocessingML 中 样式继承链时,缺乏循环检测机制。如果 DOCX 文档中存在相互引用的样式(即样式 A 基于样式 B,样式 B 又基于样式 A 或自身),会导致 及相关有效样式解析路径中出现无界递归,从而引发 。 在服务器端转换或处理目录时,若处理不可信的文档,可能导致工作线程异常终止、线程池性能下降或服务中
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| org.docx4j | docx4j-core | < 11.5.14 |
affected |
| plutext | docx4j | < 11.5.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| plutext | docx4j | < 11.5.14 | - |
|
| org.docx4j | docx4j-core | < 11.5.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet