Impact
The issue is an XML External Entity (XXE) flaw that allows unauthenticated users to supply a GML layer URL that includes a malicious XML document. The GmlLayer parser does not disable external entities or DTDs, permitting the XML to reference local files or internal HTTP endpoints. As a result an attacker can read sensitive files such as operating‑system account files, Kubernetes service‑account tokens, certificates, and can also perform server‑side request forgery against internal services.
Affected Systems
The flaw appears in the MapFish Print component produced by the mapfish vendor. All releases of mapfish-print, org.mapfish.print.print-lib, and org.mapfish.print.print-servlet prior to the following fixed releases are vulnerable: 3.28.29 and older, 3.30.31 and older, 3.31.23 and older, 3.33.15 and older, and 4.0.4 and older.
Risk and Exploitability
The vulnerability receives a CVSS score of 8.6, indicating a high severity impact. Exploitation requires an attacker to send a crafted request to the /api/print3/print endpoint, which is publicly reachable if the MapFish Print service is exposed. There is no EPSS data currently available, and the flaw is not listed in CISA’s KEV catalog, but the potential for confidential data disclosure and internal network traversal makes the risk significant.
OpenCVE Enrichment
Github GHSA