CVE-2020-36640 – org.bonitasoft.connectors:bonita-connector-webservice
Package
Manager: maven
Name: org.bonitasoft.connectors:bonita-connector-webservice
Vulnerable Version: >=0 <1.3.1
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00108 pctl0.29725
Details
bonita-connector-webservice XML External Entity vulnerability A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function `TransformerConfigurationException` of the file `src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java`. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 can address this issue. The name of the patch is a12ad691c05af19e9061d7949b6b828ce48815d5. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217443.
Metadata
Created: 2023-01-05T12:30:28Z
Modified: 2023-01-11T23:01:28Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-wg99-5vrx-j2gg/GHSA-wg99-5vrx-j2gg.json
CWE IDs: ["CWE-611"]
Alternative ID: GHSA-wg99-5vrx-j2gg
Finding: F083
Auto approve: 1