Re: CVE-2023-49733: Apache Cocoon's StreamGenerator is vulnerable to XXE injection

Cédric Damioli <[email protected]> Thu, 30 Nov 2023 14:09:16 +0100
Newsgroups gmane.text.xml.cocoon.user
Organization Apache Software Foundation
Message-ID <[email protected]>
--------------m0qRBw11L7UxSdNxaV371qvi
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Hi Warell,

Yes it does ...
I think however that it should be quite straight forward to use log4j2 
instead if needed.

Cédric

Le 30/11/2023 à 12:30, warrell harries a écrit :
> Hi Cedric,
>
> Does this build still use the infamous Log4J v1. 2 jar.... I know it's 
> actually benign due to no use of the jndi but security vulnerability 
> scanners usually complain.
>
> Thanks for your work on this.
>
> Best regards
>
> Warrell
>
> On Thu, 30 Nov 2023, 11:16 Cédric Damioli, <[email protected]> wrote:
>
>     Severity: important
>
>     Affected versions:
>
>     - Apache Cocoon 2.2.0 before 2.3.0
>
>     Description:
>
>     Improper Restriction of XML External Entity Reference
>     vulnerability in Apache Cocoon.This issue affects Apache Cocoon:
>     from 2.2.0 before 2.3.0.
>
>     Users are recommended to upgrade to version 2.3.0, which fixes the
>     issue.
>
>     References:
>
>     https://cocoon.apache.org/
>     https://www.cve.org/CVERecord?id=CVE-2023-49733
>
>
>     ---------------------------------------------------------------------
>     To unsubscribe, e-mail: [email protected]
>     For additional commands, e-mail: [email protected]
>

-- 
Cédric Damioli
CMS - Java - Open Source
www.ametys.org

--------------m0qRBw11L7UxSdNxaV371qvi
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    Hi Warell,<br>
    <br>
    Yes it does ...<br>
    I think however that it should be quite straight forward to use
    log4j2 instead if needed.<br>
    <br>
    Cédric<br>
    <br>
    <div class="moz-cite-prefix">Le 30/11/2023 à 12:30, warrell harries
      a écrit :<br>
    </div>
    <blockquote type="cite"
cite="mid:CAL-6e7syBjFp63zgpqek_fDAY_MgG8Qw_+2G7fEYv493jLugQw@mail.gmail.com">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div dir="auto">Hi Cedric,
        <div dir="auto"><br>
        </div>
        <div dir="auto">Does this build still use the infamous Log4J v1.
          2 jar.... I know it's actually benign due to no use of the
          jndi but security vulnerability scanners usually complain. </div>
        <div dir="auto"><br>
        </div>
        <div dir="auto">Thanks for your work on this. </div>
        <div dir="auto"><br>
        </div>
        <div dir="auto">Best regards</div>
        <div dir="auto"><br>
        </div>
        <div dir="auto">Warrell </div>
      </div>
      <br>
      <div class="gmail_quote">
        <div dir="ltr" class="gmail_attr">On Thu, 30 Nov 2023, 11:16
          Cédric Damioli, &lt;<a href="mailto:[email protected]"
            moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>&gt;
          wrote:<br>
        </div>
        <blockquote class="gmail_quote"
style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Severity:
          important<br>
          <br>
          Affected versions:<br>
          <br>
          - Apache Cocoon 2.2.0 before 2.3.0<br>
          <br>
          Description:<br>
          <br>
          Improper Restriction of XML External Entity Reference
          vulnerability in Apache Cocoon.This issue affects Apache
          Cocoon: from 2.2.0 before 2.3.0.<br>
          <br>
          Users are recommended to upgrade to version 2.3.0, which fixes
          the issue.<br>
          <br>
          References:<br>
          <br>
          <a href="https://cocoon.apache.org/"
            rel="noreferrer noreferrer" target="_blank"
            moz-do-not-send="true" class="moz-txt-link-freetext">https://cocoon.apache.org/</a><br>
          <a href="https://www.cve.org/CVERecord?id=CVE-2023-49733"
            rel="noreferrer noreferrer" target="_blank"
            moz-do-not-send="true" class="moz-txt-link-freetext">https://www.cve.org/CVERecord?id=CVE-2023-49733</a><br>
          <br>
          <br>
---------------------------------------------------------------------<br>
          To unsubscribe, e-mail: <a
            href="mailto:[email protected]"
            target="_blank" rel="noreferrer" moz-do-not-send="true"
            class="moz-txt-link-freetext">[email protected]</a><br>
          For additional commands, e-mail: <a
            href="mailto:[email protected]" target="_blank"
            rel="noreferrer" moz-do-not-send="true"
            class="moz-txt-link-freetext">[email protected]</a><br>
          <br>
        </blockquote>
      </div>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
Cédric Damioli
CMS - Java - Open Source
<a class="moz-txt-link-abbreviated" href="http://www.ametys.org">www.ametys.org</a></pre>
  </body>
</html>

--------------m0qRBw11L7UxSdNxaV371qvi--