XML External Entity Vulnerability in Apache Cayenne's CayenneModeler Tool
CVE-2018-11758
8.1HIGH
What is CVE-2018-11758?
Apache Cayenne's CayenneModeler, a desktop GUI tool for editing ORM models stored as XML, is susceptible to an XML External Entity (XXE) vulnerability. This allows attackers to manipulate users into opening malicious XML files. If exploited, this could enable attackers to instruct the built-in XML parser to transfer files from the user's local environment to a remote server under their control. To mitigate this security risk, XXE processing has been disabled in all operations that require XML parsing within Cayenne.
Affected Version(s)
Apache Cayenne 4.1.M1
Apache Cayenne 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1
Apache Cayenne 3.1, 3.1.1, 3.1.2