Multiple Vulnerabilities in Camunda Web Application 

Issue date: 26-04-2018
Affects versions: 12.2

Issue ID: SECURITY-56

Affected Product Version(s)
These vulnerabilities affect all versions of Hippo CMS prior to 12.3.0 and 12.2.1.

Severity 
high

Description

The Camunda BPM administration interface deployed in the hippo-addon-wpm-camunda war module uses several libraries with reported vulnerabilities, which allow for various attacks including remote code execution.

This vulnerability is classified with severity high.

  • Apache Commons FileUpload was upgraded to version 1.3.3.
  • Apache Commons Email was upgraded to version 1.5.
  • RESTEasy was upgraded to version 3.0.24.Final.
  • FasterXML Jackson2 was upgraded to version 2.8.11 and the jackson-databind module was upgraded to 2.8.11.1.

Instructions

Every CMS customer is strongly advised to upgrade as soon as possible to the latest CMS maintenance release as indicated above, or higher.
There is no further action needed for the Camunda Web Application as these dependency updates are included automatically.