Description
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Remediation
References
https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions
Related Vulnerabilities
CVE-2021-25646 Vulnerability in maven package org.apache.druid:druid-core
CVE-2023-31062 Vulnerability in maven package org.apache.inlong:manager-web
CVE-2021-26296 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project
CVE-2023-41327 Vulnerability in maven package org.wiremock:wiremock-webhooks-extension
CVE-2023-46998 Vulnerability in maven package org.webjars.npm:bootbox.js