First published: Tue Nov 06 2018(Updated: )
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Syncope | >=2.0.0<=2.0.11 | |
Apache Syncope | >=2.1.0<=2.1.2 | |
maven/org.apache.syncope:syncope-core | >=2.1.0<2.1.2 | 2.1.2 |
maven/org.apache.syncope:syncope-core | <2.0.11 | 2.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17186 is a vulnerability that allows an administrator with workflow definition entitlements to perform malicious operations using DTD, such as file read, file write, and code execution.
Apache Syncope versions 2.0.0 to 2.0.11 and versions 2.1.0 to 2.1.2 are affected by CVE-2018-17186.
CVE-2018-17186 has a severity rating of 7.2 (high).
To fix CVE-2018-17186, it is recommended to upgrade to a version of Apache Syncope that is not affected by the vulnerability.
More information about CVE-2018-17186 can be found at the following reference: https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions