Re: CVE-2023-49733: Apache Cocoon's StreamGenerator is vulnerable to XXE injection

warrell harries <[email protected]> Thu, 30 Nov 2023 11:30:49 +0000
Newsgroups gmane.text.xml.cocoon.user
Message-ID <CAL-6e7syBjFp63zgpqek_fDAY_MgG8Qw_+2G7fEYv493jLugQw@mail.gmail.com>
--0000000000007a3f10060b5cfcb7
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Cedric,

Does this build still use the infamous Log4J v1. 2 jar.... I know it's
actually benign due to no use of the jndi but security vulnerability
scanners usually complain.

Thanks for your work on this.

Best regards

Warrell

On Thu, 30 Nov 2023, 11:16 C=C3=A9dric Damioli, <[email protected]> wrote=
:

> Severity: important
>
> Affected versions:
>
> - Apache Cocoon 2.2.0 before 2.3.0
>
> Description:
>
> Improper Restriction of XML External Entity Reference vulnerability in
> Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0.
>
> Users are recommended to upgrade to version 2.3.0, which fixes the issue.
>
> References:
>
> https://cocoon.apache.org/
> https://www.cve.org/CVERecord?id=3DCVE-2023-49733
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
>

--0000000000007a3f10060b5cfcb7
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">Hi Cedric,<div dir=3D"auto"><br></div><div dir=3D"auto">D=
oes this build still use the infamous Log4J v1. 2 jar.... I know it&#39;s a=
ctually benign due to no use of the jndi but security vulnerability scanner=
s usually complain.=C2=A0</div><div dir=3D"auto"><br></div><div dir=3D"auto=
">Thanks for your work on this.=C2=A0</div><div dir=3D"auto"><br></div><div=
 dir=3D"auto">Best regards</div><div dir=3D"auto"><br></div><div dir=3D"aut=
o">Warrell=C2=A0</div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr"=
 class=3D"gmail_attr">On Thu, 30 Nov 2023, 11:16 C=C3=A9dric Damioli, &lt;<=
a href=3D"mailto:[email protected]">[email protected]</a>&gt; wrote:<br=
></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-=
left:1px #ccc solid;padding-left:1ex">Severity: important<br>
<br>
Affected versions:<br>
<br>
- Apache Cocoon 2.2.0 before 2.3.0<br>
<br>
Description:<br>
<br>
Improper Restriction of XML External Entity Reference vulnerability in Apac=
he Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0.<br>
<br>
Users are recommended to upgrade to version 2.3.0, which fixes the issue.<b=
r>
<br>
References:<br>
<br>
<a href=3D"https://cocoon.apache.org/" rel=3D"noreferrer noreferrer" target=
=3D"_blank">https://cocoon.apache.org/</a><br>
<a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2023-49733" rel=3D"norefe=
rrer noreferrer" target=3D"_blank">https://www.cve.org/CVERecord?id=3DCVE-2=
023-49733</a><br>
<br>
<br>
---------------------------------------------------------------------<br>
To unsubscribe, e-mail: <a href=3D"mailto:[email protected]=
rg" target=3D"_blank" rel=3D"noreferrer">[email protected]=
g</a><br>
For additional commands, e-mail: <a href=3D"mailto:[email protected]=
.org" target=3D"_blank" rel=3D"noreferrer">[email protected]</a>=
<br>
<br>
</blockquote></div>

--0000000000007a3f10060b5cfcb7--