Vulnerability record · CVE-2020-11991 · published 11 September 2020
CVE-2020-11991: Apache Cocoon StreamGenerator XML external entity file disclosure
Apache · Cocoon
Apache Cocoon's StreamGenerator parses user-supplied XML without disabling external system entities, allowing XML External Entity (XXE) injection. An attacker can craft XML that references local files, causing the server to read and return their contents. This exposes sensitive files such as configuration or credential files on the host.
Description
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityHigh CVSS (7.5) with no authentication or interaction required, public exploit references and a very high EPSS score, though no confirmed in-the-wild KEV listing.
What it is
Apache Cocoon's StreamGenerator parses user-supplied XML without disabling external system entities, allowing XML External Entity (XXE) injection. An attacker can craft XML that references local files, causing the server to read and return their contents. This exposes sensitive files such as configuration or credential files on the host.
Impact
An attacker gains read access to arbitrary files on the server filesystem, potentially leaking credentials, configuration and other sensitive data. There is no write or code execution impact per the CVSS vector.
Attack surface
Reachable over the network via the StreamGenerator component that accepts user-provided XML; the CVSS vector shows no privileges or user interaction required. Any endpoint feeding attacker-controlled XML into StreamGenerator is exposed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.72456, 99.4th percentile) and both references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Apache Cocoon to a version that fixes the StreamGenerator XXE issue; check the vendor advisory for the fixed release.
- If patching is not immediate, disable or restrict the StreamGenerator component and reject untrusted XML input.
- Configure the XML parser to disable external entity and DTD processing (e.g., disallow-doctype-decl, external-general-entities and external-parameter-entities off).
- Run the service with least privilege and restrict filesystem read access so leaked files are limited.
- Place the service behind a WAF or input filter that blocks DOCTYPE and external entity declarations in XML payloads.
Detection
- Search application and access logs for XML requests containing DOCTYPE, ENTITY or SYSTEM keywords.
- Monitor for outbound or local file reads triggered by XML parsing, especially requests to unusual file paths.
- Alert on StreamGenerator endpoint requests with XML bodies from untrusted sources.
- Review server file access logs for reads of sensitive files (e.g., /etc/passwd, config files) correlated with web requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://lists.apache.org/thread.html/r77add973ea521185e1a90aca00ba9dae7caa8d8b944d92421702bb54%40%3Cusers.cocoon.apache. | ExploitMailing ListVendor Advisory |
| https://lists.apache.org/thread.html/r77add973ea521185e1a90aca00ba9dae7caa8d8b944d92421702bb54%40%3Cusers.cocoon.apache. | ExploitMailing ListVendor Advisory |
Track CVE-2020-11991 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11991), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.