FixVibe
Covered by FixVibehigh

Alkacon OpenCms XXE Information Disclosure (CVE-2023-42344)

Alkacon OpenCms versions before 10.5.1 are associated with CVE-2023-42344 / GHSA-rcc6-6q2f-m2cw, an XXE information-disclosure advisory. FixVibe repo scans now flag target-specific Maven pom.xml evidence as a version-based advisory, without claiming XXE exploit confirmation.

CVE-2023-42344GHSA-rcc6-6q2f-m2cwCWE-611

Attacker Impact

An affected OpenCms runtime can expose sensitive host information if the vulnerable CMIS servlet is deployed and reachable [S2]. FixVibe treats repository matches as patch-priority dependency evidence, not proof that the scanned application exposed local files or internal resources.

Root Cause

The advisory is tracked as CWE-611 in org.opencms:opencms-core versions before 10.5.1 [S1][S2]. The issue affects OpenCms XML-processing behavior in the vulnerable release range [S2].

Concrete Fixes

Upgrade org.opencms:opencms-core to 10.5.1 or newer, rebuild the OpenCms WAR, server installation, or container image that production actually runs, and redeploy the fixed artifact [S1][S2]. If the dependency is only inherited by a parent POM or dormant module, confirm whether it is part of the deployed runtime before closing the advisory.

FixVibe coverage

FixVibe GitHub repo scans now check Maven pom.xml dependencies for org.opencms:opencms-core versions before 10.5.1. A finding is reported as a version-based advisory with the file path, detected version or constraint, confidence, CVE/GHSA IDs, and fixed version. FixVibe does not send XML payloads or claim the affected servlet is deployed and reachable from this static evidence.