Description
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Remediation
References
https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions
Related Vulnerabilities
CVE-2023-40348 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook
CVE-2023-24455 Vulnerability in maven package io.jenkins.plugins:visualexpert
CVE-2023-49383 Vulnerability in maven package com.jfinal:jfinal
CVE-2020-7015 Vulnerability in npm package kibana
CVE-2019-10446 Vulnerability in maven package org.jenkins-ci.plugins:vmanager-plugin