Description
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Remediation
References
https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions
Related Vulnerabilities
CVE-2019-10412 Vulnerability in maven package com.inedo.proget:inedo-proget
CVE-2018-1000410 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2014-2062 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2014-3503 Vulnerability in maven package org.apache.syncope:syncope-core
CVE-2022-24289 Vulnerability in maven package org.apache.cayenne:cayenne-server