Description
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Remediation
References
https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions
Related Vulnerabilities
CVE-2019-10311 Vulnerability in maven package org.jenkins-ci.plugins:ansible-tower
CVE-2023-44487 Vulnerability in maven package io.netty:netty-codec-http2
CVE-2021-33829 Vulnerability in npm package ckeditor4
CVE-2020-2226 Vulnerability in maven package org.jenkins-ci.plugins:matrix-project
CVE-2021-21347 Vulnerability in maven package com.thoughtworks.xstream:xstream