An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
2018-11-06T20:29:00.217
2024-11-21T03:54:02.740
Modified
CVSSv3.0: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | apache | syncope | ≤ 2.0.11 | Yes |
| Application | apache | syncope | ≤ 2.1.2 | Yes |