Description
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Remediation
References
https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions
Related Vulnerabilities
CVE-2018-1322 Vulnerability in maven package org.apache.syncope:syncope-core
CVE-2020-12480 Vulnerability in maven package com.typesafe.play:play_2.11
CVE-2023-50779 Vulnerability in maven package com.cloudtp.jenkins:paaslane-estimate
CVE-2020-11976 Vulnerability in maven package org.apache.wicket:wicket-core
CVE-2017-5635 Vulnerability in maven package org.apache.nifi:nifi-web-security