CVE-2023-41034
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-611
Restricción incorrecta de referencia a entidad externa XML (XXE)
Fecha de publicación:
31/08/2023
Última modificación:
06/09/2023
Descripción
*** Pendiente de traducción *** Eclipse Leshan is a device management server and client Java implementation. In affected versions DDFFileParser` and `DefaultDDFFileValidator` (and so `ObjectLoader`) are vulnerable to `XXE Attacks`. A DDF file is a LWM2M format used to store LWM2M object description. Leshan users are impacted only if they parse untrusted DDF files (e.g. if they let external users provide their own model), in that case they MUST upgrade to fixed version. If you parse only trusted DDF file and validate only with trusted xml schema, upgrading is not mandatory. This issue has been fixed in versions 1.5.0 and 2.0.0-M13. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:eclipse:leshan:*:*:*:*:*:*:*:* | 1.5.0 (excluyendo) | |
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone1:*:*:*:*:*:* | ||
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone10:*:*:*:*:*:* | ||
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone11:*:*:*:*:*:* | ||
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone12:*:*:*:*:*:* | ||
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone2:*:*:*:*:*:* | ||
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone3:*:*:*:*:*:* | ||
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone4:*:*:*:*:*:* | ||
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone5:*:*:*:*:*:* | ||
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone6:*:*:*:*:*:* | ||
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone7:*:*:*:*:*:* | ||
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone8:*:*:*:*:*:* | ||
| cpe:2.3:a:eclipse:leshan:2.0.0:milestone9:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://github.com/eclipse-leshan/leshan/commit/29577d2879ba8e7674c3b216a7f01193fc7ae013
- https://github.com/eclipse-leshan/leshan/commit/4d3e63ac271a817f81fba3e3229c519af7a3049c
- https://github.com/eclipse-leshan/leshan/security/advisories/GHSA-wc9j-gc65-3cm7
- https://github.com/eclipse-leshan/leshan/wiki/Adding-new-objects#the-lwm2m-model
- https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing



