GHSA-vc3x-72q4-g3p5
MODERATECVE-2017-7545It was discovered that the XmlUtils class in jbpmmigration performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.
- Affected
- <= 0.15
- Fixed in
- not stated
- Weakness
- CWE-611
- Published
- 2022-05-13
- Source
- github