CVE-2020-36640

A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 is able to address this issue. The patch is named a12ad691c05af19e9061d7949b6b828ce48815d5. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217443.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bonitasoft:webservice_connector:*:*:*:*:*:*:*:*

History

11 Apr 2024, 01:08

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en bonitasoft bonita-connector-webservice hasta 1.3.0 y clasificada como problemática. Esto afecta la función TransformerConfigurationException del archivo src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. La manipulación conduce a una referencia de entidad externa xml. La actualización a la versión 1.3.1 puede solucionar este problema. El parche se llama a12ad691c05af19e9061d7949b6b828ce48815d5. Se recomienda actualizar el componente afectado. El identificador asociado de esta vulnerabilidad es VDB-217443.

20 Oct 2023, 14:15

Type Values Removed Values Added
Summary A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 is able to address this issue. The name of the patch is a12ad691c05af19e9061d7949b6b828ce48815d5. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217443. A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 is able to address this issue. The patch is named a12ad691c05af19e9061d7949b6b828ce48815d5. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217443.

11 Jan 2023, 18:34

Type Values Removed Values Added
References (MISC) https://vuldb.com/?id.217443 - (MISC) https://vuldb.com/?id.217443 - Third Party Advisory
References (MISC) https://github.com/bonitasoft/bonita-connector-webservice/pull/17 - (MISC) https://github.com/bonitasoft/bonita-connector-webservice/pull/17 - Patch, Third Party Advisory
References (MISC) https://vuldb.com/?ctiid.217443 - (MISC) https://vuldb.com/?ctiid.217443 - Third Party Advisory
References (MISC) https://github.com/bonitasoft/bonita-connector-webservice/releases/tag/1.3.1 - (MISC) https://github.com/bonitasoft/bonita-connector-webservice/releases/tag/1.3.1 - Release Notes, Third Party Advisory
References (MISC) https://github.com/bonitasoft/bonita-connector-webservice/commit/a12ad691c05af19e9061d7949b6b828ce48815d5 - (MISC) https://github.com/bonitasoft/bonita-connector-webservice/commit/a12ad691c05af19e9061d7949b6b828ce48815d5 - Patch, Third Party Advisory
CPE cpe:2.3:a:bonitasoft:webservice_connector:*:*:*:*:*:*:*:*
First Time Bonitasoft
Bonitasoft webservice Connector
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

05 Jan 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-05 10:15

Updated : 2024-04-11 01:08


NVD link : CVE-2020-36640

Mitre link : CVE-2020-36640

CVE.ORG link : CVE-2020-36640


JSON object : View

Products Affected

bonitasoft

  • webservice_connector
CWE
CWE-611

Improper Restriction of XML External Entity Reference