Description
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
Remediation
References
https://github.com/BigBadaboom/androidsvg/issues/122
Related Vulnerabilities
CVE-2020-5497 Vulnerability in maven package org.mitre:openid-connect-server-webapp
CVE-2020-7780 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.12
CVE-2022-25345 Vulnerability in npm package @discordjs/opus
CVE-2020-8141 Vulnerability in maven package org.webjars.bowergithub.olado:dot