XXE Vulnerability in Apache Syncope Impacting Workflow Definitions
CVE-2018-17186
7.2HIGH
What is CVE-2018-17186?
This vulnerability allows an administrator with workflow definition entitlements in Apache Syncope to exploit XML External Entity (XXE) attacks through the use of Document Type Definitions (DTD). This can result in unauthorized access to sensitive files, modification of data, and potential remote code execution, thereby compromising the security and integrity of the application.
Affected Version(s)
Apache Syncope Apache Syncope releases prior to 2.0.11 and 2.1.2