DoS attack vulnerabilities in Apache Sanselan
Issue date: 27-10-2020Affects versions: 13.4, 12.6
Issue ID: SECURITY-111
Affected Product Version(s)
13.4.3, 12.6.10 (and previous patch releases)
Severity
low
Description
The Apache Senselan library, used to process images in previous versions of brXM, could be manipulated to use excessive CPU in response to loading a malicious image. This vulnerability could only be exploited by an authenticated user with a specially-crafted attack, so it is considered low severity.
See: CVE-2018-17201 and CVE-2018-17202
The Senselan library has been replaced with an alternative library in versions 13.4.4 and 12.6.11. Note that a project that uses the Senselan library directly will also need to use an alternative. Versions 14.0.0 and above of brXM are not vulnerable, because they already used an alternative image processing library.
Instructions
Customers are recommended to upgrade to the latest maintenance or minor releases as indicated above. This can be done by simply incrementing the version number of the parent POM for the implementation project.