CVE-2020-36640
Summary
| CVE | CVE-2020-36640 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-05 10:15:00 UTC |
| Updated | 2023-11-16 02:25:00 UTC |
| Description | A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 is able to address this issue. The patch is named a12ad691c05af19e9061d7949b6b828ce48815d5. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217443. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bonitasoft | Webservice Connector | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release Release 1.3.1 · bonitasoft/bonita-connector-webservice · GitHub | MISC | github.com | |
| vuldb.com | MISC | vuldb.com | |
| fix(vulnerabilities): fix XXE attacks vulnerabilities and other code smell by alachambre · Pull Request #17 · bonitasoft/bonita-connector-webservice · GitHub | MISC | github.com | |
| fix(vulnerabilities): fix XXE attacks vulnerabilities and other code … · bonitasoft/bonita-connector-webservice@a12ad69 · GitHub | MISC | github.com | |
| vuldb.com | MISC | vuldb.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.