maven package report

Is org.bonitasoft.connectors:bonita-connector-webservice safe?

1 known vulnerability, worst severity CRITICAL.

cvss
5.5

how bad it is if exploited, out of 10

epss
0.80%

chance of exploitation in the next 30 days

xyz score
4.0

CyberXYZ composite, out of 10

fig. 01 — GHSA-wg99-5vrx-j2gg, the advisory selected below

// advisories

GHSA-wg99-5vrx-j2gg

CRITICALCVE-2020-36640

A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 can address this issue. The name of the patch is a12ad691c

Affected
< 1.3.1
Fixed in
1.3.1
Weakness
CWE-611
Published
2023-01-05
Source
github

GHSANVDMITREreferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 01:57 UTC. The most recent advisory here was published 2023-01-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.bonitasoft.connectors:bonita-connector-webservice safe? maven package security report | CyberXYZ