Improper Restriction of XML External Entity Reference in bedework:bw-webdav
High severity
GitHub Reviewed
Published
Dec 19, 2018
to the GitHub Advisory Database
•
Updated May 15, 2024
Description
Published to the GitHub Advisory Database
Dec 19, 2018
Reviewed
Jun 16, 2020
Last updated
May 15, 2024
Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/servlet/common/MethodBase.java and webdav/servlet/common/PostRequestPars.java.
References