cayenne-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Andrus Adamchik <aadamc...@apache.org>
Subject CVE-2018-11758: Apache Cayenne XXE Vulnerability in CayenneModeler GUI tool
Date Wed, 22 Aug 2018 17:11:51 GMT
CVE-2018-11758: Apache Cayenne XXE Vulnerability in CayenneModeler GUI tool 

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Cayenne 4.1.M1
Cayenne 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1
Cayenne 3.1, 3.1.1, 3.1.2
The unsupported Cayenne 2.0.x, 3.0.x versions may be also affected

Description:
CayenneModeler is a desktop GUI tool for working with Cayenne ORM models stored as XML files.
If an attacker tricks a user of CayenneModeler into opening a malicious XML file, the attacker
will be able to instruct the XML parser built into CayenneModeler to transfer files from a
local
machine to a remote machine controlled by the attacker. The cause of the issue is XML 
parser processing XML External Entity (XXE) declarations included in XML. The vulnerability
is
addressed in Cayenne by disabling XXE processing in all operations that require XML parsing.

Mitigation:
4.1.x users should upgrade to 4.1.M2 or newer.
4.0.x users should upgrade to 4.0 (GA release).
3.1.x users should upgrade to 3.1.3.

References: 
https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing

---
Andrus Adamchik
Apache Cayenne PMC
Mime
View raw message