CVE-2020-11991
Apache cocoon Improper Restriction of XML External Entity Reference
Record summary
CVE-2020-11991 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 25, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
cocoonBrowse Apache / cocoon | VulnCheck | Version data not supplied | |
Apache Cocoon | CVE List | Apache Cocoon 2.1.0 to 2.1.12 | affected |
Nuclei templates
1ProjectDiscoveryHIGHApache Cocoon 2.1.12 - XML InjectionCVSS 7.5
Apache Cocoon 2.1.12 is susceptible to XML injection. When using the StreamGenerator, the code parses a user-provided XML. A specially crafted XML, including external system entities, can be used to access any file on the server system.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and remote code execution.
Remediation
Upgrade to Apache Cocoon 2.1.13 or later.
Source: ProjectDiscovery