QID 731224
Date Published: 2024-03-18
QID 731224: Apache Cocoon Extensible Markup Language (XML) Injection Vulnerability
Apache Cocoon, is an open source web application framework built around the concepts of Pipeline, separation of concerns, and component-based web development.
Apache Cocoon contains a vulnerability when processing user user-provided XML data using StreamGenerator. An unauthenticated, remote attacker could exploit this vulnerability by transmitting a crafted XML, including external system entities, to access any file on the targeted server.
Affected Versions:
Apache Cocoon 2.1.12 and prior
QID Detection Logic:
This unauthenticated QID detects vulnerable versions of Apache Cocoon based on the self reported version exposed by the application.
Successful exploitation allows an unauthenticated, remote attacker to gain access to local files, which may contain sensitive data such as passwords or private user data, using file: schemes or relative paths in the system identifier.
- Apache Cocoon security vulnerability -
lists.apache.org/thread/6xg5j4knfczwdhggo3t95owqzol37k1b
CVEs related to QID 731224
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Cocoon 2.1.13 or later |
|