Flowable flowable-engine 8.0.0 之前的版本存在 XML 外部实体注入漏洞,该漏洞位于 中。由于在解析已部署的 BPMN 资源时未禁用外部实体解析,拥有流程部署权限的攻击者可以在 BPMN 文件中嵌入包含外部实体的 DOCTYPE 声明,从而在计算图表布局时读取任意本地文件或向内部网络端点发起请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| flowable | flowable-engine | 0 ~ 8.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet