PT-2023-11810 · Bonitasoft · Bonita-Connector-Webservice

CVE-2020-36640

·

Publicado

2023-01-05

·

Atualizado

2024-05-17

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bonitasoft bonita-connector-webservice versions up to 1.3.0
Description A problematic issue was found in the software, affecting the TransformerConfigurationException function of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. The manipulation leads to xml external entity reference.
Recommendations For bonitasoft bonita-connector-webservice versions up to 1.3.0, upgrade to version 1.3.1 to address this issue. As a temporary workaround, consider disabling the TransformerConfigurationException function until the patch is applied. Restrict access to the affected component to minimize the risk of exploitation.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-36640
GHSA-WG99-5VRX-J2GG

Produtos afetados

Bonita-Connector-Webservice