CVE-2017-7545 – org.jbpm.jbpm5:jbpmmigration
Package
Manager: maven
Name: org.jbpm.jbpm5:jbpmmigration
Vulnerable Version: >=0 <=0.15
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00856 pctl0.74132
Details
XML External Entity Reference in jbpmmigration It was discovered that the XmlUtils class in jbpmmigration performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks. The related jbpm-designer project removed use of jbpmmigration completely as a result.
Metadata
Created: 2022-05-13T01:36:17Z
Modified: 2022-11-04T18:42:12Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vc3x-72q4-g3p5/GHSA-vc3x-72q4-g3p5.json
CWE IDs: ["CWE-611"]
Alternative ID: GHSA-vc3x-72q4-g3p5
Finding: F083
Auto approve: 1