CVE Vulnerabilities

CVE-2023-6280

Improper Restriction of XML External Entity Reference

Published: Dec 19, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Wps 52north * 4.0.0 (excluding)
Wps 52north 4.0.0-beta1 (including) 4.0.0-beta1 (including)
Wps 52north 4.0.0-beta10 (including) 4.0.0-beta10 (including)
Wps 52north 4.0.0-beta2 (including) 4.0.0-beta2 (including)
Wps 52north 4.0.0-beta3 (including) 4.0.0-beta3 (including)
Wps 52north 4.0.0-beta4 (including) 4.0.0-beta4 (including)
Wps 52north 4.0.0-beta5 (including) 4.0.0-beta5 (including)
Wps 52north 4.0.0-beta6 (including) 4.0.0-beta6 (including)
Wps 52north 4.0.0-beta7 (including) 4.0.0-beta7 (including)
Wps 52north 4.0.0-beta8 (including) 4.0.0-beta8 (including)
Wps 52north 4.0.0-beta9 (including) 4.0.0-beta9 (including)

Potential Mitigations

References