Multiple DOS and XXE Vulnerabilities in Apache POI
Issue date: 26-04-2018Affects versions: 12.2, 11.2, 10.2
Issue ID: SECURITY-51
Affected Product Version(s)
These vulnerabilities affects all versions of both CMS and delivery applications based on Hippo CMS prior to 12.3.0, 12.2.1, 11.2.7, and 10.2.11.
Severity
high
Description
6 vulnerabilities have been reported against the Apache POI library, which allow various attacks, including XML entity expansion and denial of service. Customers may also be vulnerable in other ways via use of these libraries in their own code.
See CVE-2012-0213, CVE-2014-9527, CVE-2014-3574, CVE-2014-9527, CVE-2016-5000, CVE-2017-5644.
The affected Apache POI library has been updated to version 3.17 in all supported CMS maintenance versions 10.2.11, 11.2.7, 12.2.1, and 12.3.0.
- The version used in the 10.2 and 11.2 series was previously 3.8.
- The version used in the 12.2 and 12.3 series was previously 3.11.
Instructions
Every CMS customer is strongly advised to upgrade as soon as possible to the latest CMS maintenance release as indicated above, or higher.
Because the upgrade for these CMS maintenance versions may require some additonal steps and verification, specific upgrade documentation is available to our customers for upgrading to version 10.2.11, 11.2.7, or to 12.2.1 and 12.3.0 (login required).