Description
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Remediation
References
https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions
Related Vulnerabilities
CVE-2021-41616 Vulnerability in maven package org.apache.ddlutils:ddlutils
CVE-2023-24433 Vulnerability in maven package io.jenkins.plugins:macstadium-orka
CVE-2023-27903 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-28673 Vulnerability in maven package org.jenkinsci.plugins:octoperf
CVE-2020-7743 Vulnerability in maven package org.webjars.npm:mathjs