Skip to content
OracleGHSA-f6v3-cvph-88fm

unrestricted XML decoding

LowPublished Apr 7, 2021

### Impact Decoding objects serialized in XML (Configuration, History, plugin Configuration) can result in arbitrary execution. This is especially true when using the RESTful API call to set the configuration. Note that this requires the use of bearer token if using outside of localhost. Discovered by Bobby Rauch (Accenture). ### Patches The XML decoders used in the project were patched in 1.6.9 and later. ### Workarounds N/A ### References https://github.com/oracle/opengrok/pull/3526 https://github.com/oracle/opengrok/pull/3527 https://github.com/oracle/opengrok/pull/3528

GitHub advisory

Affected versions

PackageAffectedFixed in
opengrok
Product
< 1.6.91.6.9
Details and references

More Oracle advisories

All Oracle
Advisory
Oracle Public Sector Financials (International): takeover via Authorization
High8.0Jul 21
Oracle Java SE: flaw in JSSE
Medium5.3Jul 21
Oracle Application Testing Suite: unauthenticated attacker could compromise...
Critical9.8Jul 21
Oracle Commerce Service Center: data tampering via Commerce Service Center
Medium6.1Jul 21
Oracle Retail Xstore Point of Service: data exposure via Xstore Mobile
Medium4.3Jul 21
Oracle Retail Xstore Point of Service: data exposure via Xstore Mobile
Low3.3Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.