logo

CVE-2020-36640 org.bonitasoft.connectors:bonita-connector-webservice

Package

Manager: maven
Name: org.bonitasoft.connectors:bonita-connector-webservice
Vulnerable Version: >=0 <1.3.1

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00108 pctl0.29725

Details

bonita-connector-webservice XML External Entity vulnerability A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function `TransformerConfigurationException` of the file `src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java`. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 can address this issue. The name of the patch is a12ad691c05af19e9061d7949b6b828ce48815d5. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217443.

Metadata

Created: 2023-01-05T12:30:28Z
Modified: 2023-01-11T23:01:28Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-wg99-5vrx-j2gg/GHSA-wg99-5vrx-j2gg.json
CWE IDs: ["CWE-611"]
Alternative ID: GHSA-wg99-5vrx-j2gg
Finding: F083
Auto approve: 1