5.8. Hangs
5.8.1. [Critical] Potential uncontrolled CPU usage when parsing Governance or Permissions Documents due to a vulnerability in Expat
The Security Plugins rely on the Core Libraries to parse Governance and Permissions Documents. The Core Libraries, in turn, rely on Expat (third-party software) to parse XML documents. Expat was known to be affected by CVE-2023-52425. This bug has been fixed by upgrading Expat from version 2.4.8 to version 2.6.2. The impact on Connext applications of using the previous version was as follows:
The attacker could exploit the bug by having the victim’s Permissions CA sign a Governance or Permissions Document with a large token. This exploitation requires high privileges.
To exploit a Governance Document, the attacker would need access to the victim’s file system.
To exploit a Permissions Document, the attacker would need access to the victim’s network.
The application could use an uncontrollable amount of CPU and fall victim to a denial-of-service attack.
[RTI Issue ID SEC-2413]