Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS0ycWM4LXI2NjMtdjg2NM4AA1Qr

OpenNMS Horizon XXE Injection Vulnerability

XXE injection in /rtc/post/ endpoint in OpenNMS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which can be used for instance to force Horizon to make arbitrary HTTP requests to internal and external services. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.

Permalink: https://github.com/advisories/GHSA-2qc8-r663-v864
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycWM4LXI2NjMtdjg2NM4AA1Qr
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 9 months ago
Updated: 6 months ago


CVSS Score: 8.8
CVSS vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

Identifiers: GHSA-2qc8-r663-v864, CVE-2023-0871
References: Repository: https://github.com/OpenNMS/opennms
Blast Radius: 1.0

Affected Packages

maven:org.opennms.core:org.opennms.core.xml
Affected Version Ranges: >= 31.0.8, < 32.0.2
Fixed in: 32.0.2