OracleGHSA-f6v3-cvph-88fm
unrestricted XML decoding
LowPublished Apr 7, 2021
### Impact Decoding objects serialized in XML (Configuration, History, plugin Configuration) can result in arbitrary execution. This is especially true when using the RESTful API call to set the configuration. Note that this requires the use of bearer token if using outside of localhost. Discovered by Bobby Rauch (Accenture). ### Patches The XML decoders used in the project were patched in 1.6.9 and later. ### Workarounds N/A ### References https://github.com/oracle/opengrok/pull/3526 https://github.com/oracle/opengrok/pull/3527 https://github.com/oracle/opengrok/pull/3528
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| opengrok Product | < 1.6.9 | 1.6.9 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Oracle advisories
All Oracle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 21 | Oracle Public Sector Financials (International): takeover via Authorization | High8.0 | No fix yet |
| Jul 21 | Oracle Java SE: flaw in JSSE | Medium5.3 | No fix yet |
| Jul 21 | Oracle Application Testing Suite: unauthenticated attacker could compromise... | Critical9.8 | No fix yet |
| Jul 21 | Oracle Commerce Service Center: data tampering via Commerce Service Center | Medium6.1 | No fix yet |
| Jul 21 | Oracle Retail Xstore Point of Service: data exposure via Xstore Mobile | Medium4.3 | No fix yet |
| Jul 21 | Oracle Retail Xstore Point of Service: data exposure via Xstore Mobile | Low3.3 | No fix yet |