GHSA-wg99-5vrx-j2gg
CRITICALCVE-2020-36640A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 can address this issue. The name of the patch is a12ad691c
- Affected
- < 1.3.1
- Fixed in
- 1.3.1
- Weakness
- CWE-611
- Published
- 2023-01-05
- Source
- github