XXE vulnerability in Apache PDFBox (CVE-2016-2175)
Issue date: 26-04-2018Affects versions: 12.2, 11.2, 10.2
Issue ID: SECURITY-31
Affected Product Version(s)
This vulnerability affects all versions of both CMS and delivery applications based on Hippo CMS prior to 12.3.0, 12.2.1, 11.2.7, and 10.2.11.
Severity 
high
Description
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF. See: CVE-2016-2175
This vulnerability is classified with severity high, and may (also) apply to project specific usages of the Apache PDFBox libraries within a Hippo CMS project.
The Apache PDFBox version in all supported CMS maintenance versions 10.2.11, 11.2.7 and 12.2.1 has been updated from version 1.8.8 to:
- Apache PDFBox version 2.0.8 for the Hippo CMS and Repository (CMS authoring web application)
- Apache PDFBox version 1.8.13 for the optional Enterprise EForms addon (SITE delivery web application)
Instructions
Every CMS customer is strongly advised to upgrade as soon as possible to the latest CMS maintenance release as indicated above, or higher.
Because the upgrade for these CMS maintenance versions may require some additonal steps and verification, specific upgrade documentation is available to our customers for upgrading to version 10.2.11, 11.2.7, or to 12.2.1 and 12.3.0 (login required).