CVE-2017-7545: Improper Restriction of XML External Entity Reference
(updated )
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
References
- access.redhat.com/errata/RHSA-2017:3354
- access.redhat.com/errata/RHSA-2017:3355
- bugzilla.redhat.com/show_bug.cgi?id=1474822
- bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7545
- github.com/advisories/GHSA-vc3x-72q4-g3p5
- github.com/kiegroup/jbpm-designer/commit/a143f3b92a6a5a527d929d68c02a0c5d914ab81d
- nvd.nist.gov/vuln/detail/CVE-2017-7545
Detect and mitigate CVE-2017-7545 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →