CVE-2018-11758: Apache Cayenne XXE Vulnerability in CayenneModeler GUI tool 

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Cayenne 4.1.M1
Cayenne 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1
Cayenne 3.1, 3.1.1, 3.1.2
The unsupported Cayenne 2.0.x, 3.0.x versions may be also affected

Description:
CayenneModeler is a desktop GUI tool for working with Cayenne ORM models stored 
as XML files.
If an attacker tricks a user of CayenneModeler into opening a malicious XML 
file, the attacker
will be able to instruct the XML parser built into CayenneModeler to transfer 
files from a local
machine to a remote machine controlled by the attacker. The cause of the issue 
is XML 
parser processing XML External Entity (XXE) declarations included in XML. The 
vulnerability is
addressed in Cayenne by disabling XXE processing in all operations that require 
XML parsing.

Mitigation:
4.1.x users should upgrade to 4.1.M2 or newer.
4.0.x users should upgrade to 4.0 (GA release).
3.1.x users should upgrade to 3.1.3.

References: 
https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing

---
Andrus Adamchik
Apache Cayenne PMC

Reply via email to