CVE-2018-11758: Apache Cayenne XXE Vulnerability in CayenneModeler GUI tool

Andrus Adamchik <[email protected]>
Newsgroups gmane.comp.java.cayenne.devel
Message-ID <[email protected]>
CVE-2018-11758: Apache Cayenne XXE Vulnerability in CayenneModeler GUI tool 

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Cayenne 4.1.M1
Cayenne 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1
Cayenne 3.1, 3.1.1, 3.1.2
The unsupported Cayenne 2.0.x, 3.0.x versions may be also affected

Description:
CayenneModeler is a desktop GUI tool for working with Cayenne ORM models stored as XML files.
If an attacker tricks a user of CayenneModeler into opening a malicious XML file, the attacker
will be able to instruct the XML parser built into CayenneModeler to transfer files from a local
machine to a remote machine controlled by the attacker. The cause of the issue is XML 
parser processing XML External Entity (XXE) declarations included in XML. The vulnerability is
addressed in Cayenne by disabling XXE processing in all operations that require XML parsing.

Mitigation:
4.1.x users should upgrade to 4.1.M2 or newer.
4.0.x users should upgrade to 4.0 (GA release).
3.1.x users should upgrade to 3.1.3.

References: 
https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing

---
Andrus Adamchik
Apache Cayenne PMC
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.