PT-2026-8312 · Unknown · Opencc Jflow
Maoqiu
·
Publicado
2026-02-16
·
Atualizado
2026-02-16
·
CVE-2026-2536
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
opencc JFlow versions prior to 20260129
Description
A flaw exists in opencc JFlow’s Workflow Engine component, specifically within the
Imp Done function of the src/main/java/bp/wf/httphandler/WF Admin AttrFlow.java file. This issue stems from the manipulation of the File argument, leading to XML External Entity (XXE) reference. The attack can be initiated remotely. The details of this issue have been publicly disclosed, and the project has been notified but has not yet responded.Recommendations
Update opencc JFlow to a version later than 20260129.
As a temporary workaround, restrict access to the
WF Admin AttrFlow.java file.
Avoid using the File argument in the Imp Done function until the issue is resolved.Exploit
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Opencc Jflow