Description
An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory.
Remediation
References
https://gist.github.com/spookhorror/9519fc66d3946e887e4a86c06ddbee0e
https://github.com/opencrx/opencrx/commit/ce7a71db0bb34ecbcb0e822d40598e410a48b399
Related Vulnerabilities
CVE-2019-18213 Vulnerability in maven package org.lsp4xml:lsp4xml-extensions
CVE-2020-2183 Vulnerability in maven package org.jenkins-ci.plugins:copyartifact
CVE-2021-32818 Vulnerability in npm package haml-coffee
CVE-2020-8203 Vulnerability in npm package lodash
CVE-2020-7961 Vulnerability in maven package com.liferay.portal:com.liferay.portal.impl