Skip to content

[GHSA-jwwr-fjgh-cv2x] Improper Restriction of XML External Entity Reference in Castor#7409

Open
kmoens wants to merge 1 commit intokmoens/advisory-improvement-7409from
kmoens-GHSA-jwwr-fjgh-cv2x
Open

[GHSA-jwwr-fjgh-cv2x] Improper Restriction of XML External Entity Reference in Castor#7409
kmoens wants to merge 1 commit intokmoens/advisory-improvement-7409from
kmoens-GHSA-jwwr-fjgh-cv2x

Conversation

@kmoens
Copy link
Copy Markdown

@kmoens kmoens commented Apr 16, 2026

Updates

  • Affected products

Comments
This is an older artifact name for the same product, also detected by Maven Repository: https://mvnrepository.com/artifact/castor/castor

Copilot AI review requested due to automatic review settings April 16, 2026 11:46
@github-actions github-actions bot changed the base branch from main to kmoens/advisory-improvement-7409 April 16, 2026 11:47
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the GitHub-reviewed advisory for GHSA-jwwr-fjgh-cv2x (Castor XXE) to include an additional Maven coordinate representing an older/alternate artifact name for the same product.

Changes:

  • Bumped the advisory modified timestamp.
  • Added a new affected Maven package entry for castor:castor with the same affected range pattern used for the existing alternate coordinate.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants