S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-11991 Scanner

CVE-2020-11991 scanner - XML External Entity vulnerability in Apache Cocoon

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-11991
7.5
CVSS

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache Cocoonby n/a
Apache Cocoon 2.1.0 to 2.1.12
Updated Aug 21, 2026View on NVD →
Detail

Apache Cocoon is an open-source framework used for building web applications. It offers a platform for creating content-oriented applications that respond to requests from various sources such as HTML, PDF, etc. and allows users to manage and distribute content in multiple languages. Apache Cocoon combines various technologies including XSLT, XML, Java, and web services, making it a powerful tool for developing web applications that can support different technologies. The software has been used in various industries including Government, Education, Health, and Media industries.

Recently, a vulnerability, CVE-2020-11991, was detected in the StreamGenerator component of the Apache Cocoon software. This vulnerability could allow any user to execute arbitrary code by leveraging XML External Entity(XXE) injection. The vulnerability can be triggered if a specially crafted XML file is uploaded and processed by the StreamGenerator component. 

This vulnerability can have serious consequences for businesses and organizations that use the Apache Cocoon software. If exploited, an attacker can gain access to sensitive information or damage the entire system. They could also create a backdoor allowing them access to the system as an administrator, thus compromising data and affecting the integrity of the entire network. The result could be a significant financial loss and damage to the company's reputation.

In conclusion, vulnerabilities such as CVE-2020-11991 can be a major concern for businesses and organizations that use the Apache Cocoon software. It's crucial that users take the necessary precautions to prevent such vulnerabilities from being exploited and causing significant damage. With the "pro" features of the s4e.io platform, users can easily and quickly discover vulnerabilities in their digital assets giving them peace of mind knowing their system is secure.

 

REFERENCES

Solution Advice

To ensure that systems using the Apache Cocoon software are protected against CVE-2020-11991, users should take the following precautions: 

  • Regularly update and patch the Apache Cocoon software to the latest version.
  • Limit access to the StreamGenerator component to only trusted users.
  • Use input validation techniques such as Regular Expression or input filtering to prevent the insertion of malicious input.
  • Use a Web Application Firewall(WAF) to detect and block XXE attacks.
  • Follow security guidelines provided by the Apache Foundation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-11991 scanner - XML External Entity vulnerability in Apache Cocoon | S4E