kiegroup/jbpm-designer

kiegroup/jbpm-designer

Releases146
Frequency3 weeks 5 days
Last Release
Stars188
Web-based BPMN2.0 Designer for jBPM

CVE History

CVEPublishedCVSS v3CVSS v2
4 MEDIUM

It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks.

7.5 HIGH

XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2ResourceImpl.java in jbpm-designer 6.0.x and 6.2.x allows remote attackers to read arbitrary files and possibly have other unspecified impact by importing a crafted BPMN2 file.