The vendor explicitly identifies these products as affected by this CVE.
- rhoai/odh-trustyai-service-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in Apache OpenNLP. A remote attacker can exploit this vulnerability by providing a specially crafted dictionary file. This can lead to an XML External Entity (XXE) injection, which allows for the disclosure of local files or enables server-side request forgery (SSRF), where the server makes unauthorized requests to other systems.
- Remediation
- Affected
