XML External Entity injection in Drools - CVE-2021-41411
Published: September 20, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input in KieModuleMarshaller.java. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Proxy
SUSE Linux Enterprise Module for SUSE Manager Server
Oracle Communications Unified Inventory Management
image-sync-formula
saltboot-formula
inter-server-sync
inter-server-sync-debuginfo
salt-netapi-client
subscription-matcher
httpcomponents-asyncclient
susemanager-tftpsync-recv
python3-uyuni-common-libs
spacewalk-search
release-notes-susemanager-proxy
release-notes-susemanager
mgr-daemon
spacewalk-admin
spacewalk-proxy-common
spacewalk-proxy-broker
spacewalk-proxy-salt
spacewalk-proxy-redirect
spacewalk-proxy-package-manager
spacewalk-proxy-management
spacewalk-certs-tools
python3-spacewalk-certs-tools
spacecmd
python3-spacewalk-client-tools
python3-spacewalk-check
python3-spacewalk-client-setup
spacewalk-check
spacewalk-client-tools
spacewalk-client-setup
susemanager-schema
spacewalk-backend-tools
spacewalk-backend
spacewalk-backend-app
spacewalk-backend-applet
spacewalk-backend-config-files
spacewalk-backend-config-files-common
spacewalk-backend-config-files-tool
spacewalk-backend-iss
spacewalk-backend-iss-export
spacewalk-backend-package-push-server
spacewalk-backend-server
spacewalk-backend-sql
spacewalk-backend-xmlrpc
spacewalk-backend-xml-export-libs
spacewalk-backend-sql-postgresql
uyuni-config-modules
susemanager-sls
spacewalk-base
spacewalk-html
spacewalk-base-minimal-config
spacewalk-base-minimal
susemanager
susemanager-tools
spacewalk-taskomatic
spacewalk-java-postgresql
spacewalk-java-lib
spacewalk-java-config
spacewalk-java
patterns-suma_retail
patterns-suma_server
patterns-suma_proxy
susemanager-docs_en-pdf
susemanager-docs_en
susemanager-doc-indexes
drools
py27-compat-salt
How to mitigate CVE-2021-41411
image-sync-formula - update to 0.1.1661440526.b08d95b-150300.3.3.2
saltboot-formula - update to 0.1.1661440526.b08d95b-150300.3.12.2
inter-server-sync - update to 0.2.3-150300.8.22.2
inter-server-sync-debuginfo - update to 0.2.3-150300.8.22.2
salt-netapi-client - update to 0.20.0-150300.3.9.4
subscription-matcher - update to 0.29-150300.6.12.2
httpcomponents-asyncclient - update to 4.1.4-150300.3.3.2
susemanager-tftpsync-recv - update to 4.2.5-150300.3.6.2
python3-uyuni-common-libs - update to 4.2.7-150300.3.9.2
spacewalk-search - update to 4.2.8-150300.3.12.2
release-notes-susemanager-proxy - addressed in versions 4.2.9-150300.3.43.1, 4.3.2-150400.3.9.3
release-notes-susemanager - addressed in versions 4.2.9-150300.3.54.1, 4.3.2-150400.3.15.1
mgr-daemon - update to 4.2.10-150300.2.9.4
spacewalk-admin - update to 4.2.12-150300.3.15.3
spacewalk-proxy-common - update to 4.2.12-150300.3.21.3
spacewalk-proxy-broker - update to 4.2.12-150300.3.21.3
spacewalk-proxy-salt - update to 4.2.12-150300.3.21.3
spacewalk-proxy-redirect - update to 4.2.12-150300.3.21.3
spacewalk-proxy-package-manager - update to 4.2.12-150300.3.21.3
spacewalk-proxy-management - update to 4.2.12-150300.3.21.3
spacewalk-certs-tools - update to 4.2.18-150300.3.24.3
python3-spacewalk-certs-tools - update to 4.2.18-150300.3.24.3
spacecmd - update to 4.2.19-150300.4.27.2
python3-spacewalk-client-tools - update to 4.2.20-150300.4.24.3
python3-spacewalk-check - update to 4.2.20-150300.4.24.3
python3-spacewalk-client-setup - update to 4.2.20-150300.4.24.3
spacewalk-check - update to 4.2.20-150300.4.24.3
spacewalk-client-tools - update to 4.2.20-150300.4.24.3
spacewalk-client-setup - update to 4.2.20-150300.4.24.3
susemanager-schema - update to 4.2.24-150300.3.27.3
spacewalk-backend-tools - update to 4.2.24-150300.4.29.5
spacewalk-backend - update to 4.2.24-150300.4.29.5
spacewalk-backend-app - update to 4.2.24-150300.4.29.5
spacewalk-backend-applet - update to 4.2.24-150300.4.29.5
spacewalk-backend-config-files - update to 4.2.24-150300.4.29.5
spacewalk-backend-config-files-common - update to 4.2.24-150300.4.29.5
spacewalk-backend-config-files-tool - update to 4.2.24-150300.4.29.5
spacewalk-backend-iss - update to 4.2.24-150300.4.29.5
spacewalk-backend-iss-export - update to 4.2.24-150300.4.29.5
spacewalk-backend-package-push-server - update to 4.2.24-150300.4.29.5
spacewalk-backend-server - update to 4.2.24-150300.4.29.5
spacewalk-backend-sql - update to 4.2.24-150300.4.29.5
spacewalk-backend-xmlrpc - update to 4.2.24-150300.4.29.5
spacewalk-backend-xml-export-libs - update to 4.2.24-150300.4.29.5
spacewalk-backend-sql-postgresql - update to 4.2.24-150300.4.29.5
uyuni-config-modules - update to 4.2.27-150300.3.33.4
susemanager-sls - update to 4.2.27-150300.3.33.4
spacewalk-base - update to 4.2.29-150300.3.27.3
spacewalk-html - update to 4.2.29-150300.3.27.3
spacewalk-base-minimal-config - update to 4.2.29-150300.3.27.3
spacewalk-base-minimal - update to 4.2.29-150300.3.27.3
susemanager - update to 4.2.37-150300.3.41.1
susemanager-tools - update to 4.2.37-150300.3.41.1
spacewalk-taskomatic - update to 4.2.41-150300.3.43.5
spacewalk-java-postgresql - update to 4.2.41-150300.3.43.5
spacewalk-java-lib - update to 4.2.41-150300.3.43.5
spacewalk-java-config - update to 4.2.41-150300.3.43.5
spacewalk-java - update to 4.2.41-150300.3.43.5
patterns-suma_retail - update to 4.2-150300.4.12.2
patterns-suma_server - update to 4.2-150300.4.12.2
patterns-suma_proxy - update to 4.2-150300.4.12.2
susemanager-docs_en-pdf - update to 4.2-150300.12.33.2
susemanager-docs_en - update to 4.2-150300.12.33.2
susemanager-doc-indexes - update to 4.2-150300.12.33.4
drools - update to 7.17.0-150300.4.6.2
py27-compat-salt - update to 3000.3-150300.7.7.23.2