Description
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Remediation
References
https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions
Related Vulnerabilities
CVE-2022-45064 Vulnerability in maven package org.apache.sling:org.apache.sling.engine
CVE-2015-5174 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2016-0711 Vulnerability in maven package org.apache.portals.jetspeed-2:j2-admin
CVE-2018-1000185 Vulnerability in maven package org.jenkins-ci.plugins:github-branch-source