Re: CVE-2023-49733: Apache Cocoon's StreamGenerator is vulnerable to XXE injection
Cédric Damioli <[email protected]> Thu, 30 Nov 2023 14:09:16 +0100
| Newsgroups | gmane.text.xml.cocoon.user |
|---|---|
| Organization | Apache Software Foundation |
| Message-ID | <[email protected]> |
--------------m0qRBw11L7UxSdNxaV371qvi Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Hi Warell, Yes it does ... I think however that it should be quite straight forward to use log4j2 instead if needed. Cédric Le 30/11/2023 à 12:30, warrell harries a écrit : > Hi Cedric, > > Does this build still use the infamous Log4J v1. 2 jar.... I know it's > actually benign due to no use of the jndi but security vulnerability > scanners usually complain. > > Thanks for your work on this. > > Best regards > > Warrell > > On Thu, 30 Nov 2023, 11:16 Cédric Damioli, <[email protected]> wrote: > > Severity: important > > Affected versions: > > - Apache Cocoon 2.2.0 before 2.3.0 > > Description: > > Improper Restriction of XML External Entity Reference > vulnerability in Apache Cocoon.This issue affects Apache Cocoon: > from 2.2.0 before 2.3.0. > > Users are recommended to upgrade to version 2.3.0, which fixes the > issue. > > References: > > https://cocoon.apache.org/ > https://www.cve.org/CVERecord?id=CVE-2023-49733 > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > -- Cédric Damioli CMS - Java - Open Source www.ametys.org --------------m0qRBw11L7UxSdNxaV371qvi Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 8bit <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> </head> <body> Hi Warell,<br> <br> Yes it does ...<br> I think however that it should be quite straight forward to use log4j2 instead if needed.<br> <br> Cédric<br> <br> <div class="moz-cite-prefix">Le 30/11/2023 à 12:30, warrell harries a écrit :<br> </div> <blockquote type="cite" cite="mid:CAL-6e7syBjFp63zgpqek_fDAY_MgG8Qw_+2G7fEYv493jLugQw@mail.gmail.com"> <meta http-equiv="content-type" content="text/html; charset=UTF-8"> <div dir="auto">Hi Cedric, <div dir="auto"><br> </div> <div dir="auto">Does this build still use the infamous Log4J v1. 2 jar.... I know it's actually benign due to no use of the jndi but security vulnerability scanners usually complain. </div> <div dir="auto"><br> </div> <div dir="auto">Thanks for your work on this. </div> <div dir="auto"><br> </div> <div dir="auto">Best regards</div> <div dir="auto"><br> </div> <div dir="auto">Warrell </div> </div> <br> <div class="gmail_quote"> <div dir="ltr" class="gmail_attr">On Thu, 30 Nov 2023, 11:16 Cédric Damioli, <<a href="mailto:[email protected]" moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>> wrote:<br> </div> <blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Severity: important<br> <br> Affected versions:<br> <br> - Apache Cocoon 2.2.0 before 2.3.0<br> <br> Description:<br> <br> Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0.<br> <br> Users are recommended to upgrade to version 2.3.0, which fixes the issue.<br> <br> References:<br> <br> <a href="https://cocoon.apache.org/" rel="noreferrer noreferrer" target="_blank" moz-do-not-send="true" class="moz-txt-link-freetext">https://cocoon.apache.org/</a><br> <a href="https://www.cve.org/CVERecord?id=CVE-2023-49733" rel="noreferrer noreferrer" target="_blank" moz-do-not-send="true" class="moz-txt-link-freetext">https://www.cve.org/CVERecord?id=CVE-2023-49733</a><br> <br> <br> ---------------------------------------------------------------------<br> To unsubscribe, e-mail: <a href="mailto:[email protected]" target="_blank" rel="noreferrer" moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a><br> For additional commands, e-mail: <a href="mailto:[email protected]" target="_blank" rel="noreferrer" moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a><br> <br> </blockquote> </div> </blockquote> <br> <pre class="moz-signature" cols="72">-- Cédric Damioli CMS - Java - Open Source <a class="moz-txt-link-abbreviated" href="http://www.ametys.org">www.ametys.org</a></pre> </body> </html> --------------m0qRBw11L7UxSdNxaV371qvi--