Description
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.
Remediation
References
http://marc.info/?l=wink-user&m=127843482925387&w=2
https://svn.apache.org/repos/asf/wink/trunk/security/CVE-2010-2245.pdf
Related Vulnerabilities
CVE-2022-43413 Vulnerability in maven package org.jenkins-ci.plugins:job-import-plugin
CVE-2023-27603 Vulnerability in maven package org.apache.linkis:linkis-common
CVE-2018-1000836 Vulnerability in maven package org.bedework.caleng:bw-calendar-engine-impl
CVE-2022-45401 Vulnerability in maven package org.jenkinsci.plugins:associated-files
CVE-2022-36916 Vulnerability in maven package org.jenkins-ci.plugins:google-cloud-backup