Description
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Remediation
References
https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions
Related Vulnerabilities
CVE-2017-3165 Vulnerability in maven package org.apache.brooklyn:brooklyn-jsgui
CVE-2020-5413 Vulnerability in maven package org.springframework.integration:spring-integration
CVE-2018-3826 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2021-33829 Vulnerability in npm package ckeditor4
CVE-2023-28681 Vulnerability in maven package org.jenkins-ci.plugins:vs-code-metrics