Impact
The vulnerability resides in the of the Flowable engine, where external entity resolution is not disabled during XML parsing of BPMN resources. This omission allows an attacker who has permission to deploy processes to embed a DOCTYPE declaration with malicious external entities is computed, the attacker can read arbitrary local files or force the engine to make network requests to internal endpoints, exposing sensitive system information.
Affected Systems
Flowable flowable-engine versions up to and including 8.0.0 are vulnerable. The issue affects deployments of the Flowable process engine used in Java applications that parse BPMN XML. The vulnerability originates in ProcessDiagramLayoutFactory within the engine’s diagram package.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. The EPSS score of < 1% indicates a very low exploitation probability, though the vulnerability remains usable by actors with deployment privileges. The vulnerability is not listed in CISA KEV, implying no known widespread exploitation yet. The attack vector requires compromising process deployment permissions to trigger data exposure if application deployment endpoints are exposed to an untrusted user base.
OpenCVE Enrichment