Description
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.
Remediation
References
http://seclists.org/oss-sec/2017/q2/31
http://www.securityfocus.com/bid/97509
Related Vulnerabilities
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.sonos
CVE-2022-39353 Vulnerability in maven package org.webjars.npm:xmldom
CVE-2020-11974 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-dao
CVE-2019-14772 Vulnerability in maven package org.webjars.npm:verdaccio
CVE-2019-10246 Vulnerability in maven package org.eclipse.jetty:jetty-util