Description
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Remediation
References
https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions
Related Vulnerabilities
CVE-2023-46651 Vulnerability in maven package io.jenkins.plugins:warnings-ng
CVE-2018-1000665 Vulnerability in maven package org.webjars:dojo
CVE-2022-42129 Vulnerability in maven package com.liferay:com.liferay.dynamic.data.mapping.form.web
CVE-2019-10380 Vulnerability in maven package org.jenkins-ci.plugins:simple-travis-runner
CVE-2015-0279 Vulnerability in maven package org.richfaces:richfaces-a4j