Описание
Improper Restriction of XML External Entity Reference in org.apache.syncope:syncope-core
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Пакеты
Наименование
org.apache.syncope:syncope-core
maven
Затронутые версииВерсия исправления
< 2.0.11
2.0.11
Наименование
org.apache.syncope:syncope-core
maven
Затронутые версииВерсия исправления
>= 2.1.0, < 2.1.2
2.1.2
Связанные уязвимости
CVSS3: 7.2
nvd
больше 7 лет назад
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.