Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS02cXg5LXJmOWctN2ptcs4AAdyR

Improper Input Validation in Drools and jBPM

XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.

Permalink: https://github.com/advisories/GHSA-6qx9-rf9g-7jmr
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02cXg5LXJmOWctN2ptcs4AAdyR
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: over 1 year ago


Identifiers: GHSA-6qx9-rf9g-7jmr, CVE-2014-8125
References: Repository: https://github.com/droolsjbpm/drools
Blast Radius: 0.0

Affected Packages

maven:org.jbpm:jbpm-bpmn2
Dependent packages: 100
Dependent repositories: 501
Downloads:
Affected Version Ranges: <= 6.2.0.CR4
Fixed in: 6.2.0.Final
All affected versions:
All unaffected versions:
maven:org.drools:drools-core
Dependent packages: 419
Dependent repositories: 2,495
Downloads:
Affected Version Ranges: <= 6.2.0.CR4
Fixed in: 6.2.0.Final
All affected versions:
All unaffected versions: 5.0.1, 5.1.0, 5.1.1