CVE-2018-17186

HIGH7.2EPSS 0.56%

Improper Restriction of XML External Entity Reference in org.apache.syncope:syncope-core

Published: 11/6/2018Modified: 3/4/2024

Description

An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (4)

CVE-2018-17186 — Improper Restriction of XML External Entity Reference in org.apache.syncope:sync · VulnScope