Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

XXE Security Vulnerability #728

Open
scarvell opened this issue Apr 21, 2016 · 0 comments
Open

XXE Security Vulnerability #728

scarvell opened this issue Apr 21, 2016 · 0 comments

Comments

@scarvell
Copy link

scarvell commented Apr 21, 2016

Hey guys,

I tried reporting this directly to the vendor privately but they won't fix the issue unless an enterprise edition is purchased. I'm posting a Github issue so hopefully someone can provide a patch for the community edition.

Pentaho's xml parser does not disable the parsing of external entities, which is turned on by default. This is a problem because an attacker can upload a malicious XML file and read arbitrary files off the server and send the contents to a remote server.

An example of the vulnerability exists when importing a new Manage Data Sources > Import Metadata.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant