Description
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Remediation
References
https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions
Related Vulnerabilities
CVE-2019-17573 Vulnerability in maven package org.apache.cxf:cxf-rt-transports-http
CVE-2020-2253 Vulnerability in maven package org.jenkins-ci.plugins:email-ext
CVE-2020-7679 Vulnerability in npm package casperjs
CVE-2020-9480 Vulnerability in maven package org.apache.spark:spark-network-shuffle_2.11
CVE-2017-1000006 Vulnerability in maven package org.webjars.npm:plotly.js