[MAVEN:GHSA-QFJV-998W-Q48F] Improper Restriction of XML External Entity Reference in org.apache.syncope:syncope-core

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.

ID
MAVEN:GHSA-QFJV-998W-Q48F
Severity
high
URL
https://github.com/advisories/GHSA-qfjv-998w-q48f
Published
2018-11-06T23:15:46
(5 years ago)
Modified
2024-03-04T21:31:13
(6 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.syncope/syncope-core org.apache.syncope syncope-core >= 2.1.0 < 2.1.2
Fixed pkg:maven/org.apache.syncope/syncope-core org.apache.syncope syncope-core = 2.1.2
Affected pkg:maven/org.apache.syncope/syncope-core org.apache.syncope syncope-core < 2.0.11
Fixed pkg:maven/org.apache.syncope/syncope-core org.apache.syncope syncope-core = 2.0.11
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...