Description
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
Remediation
References
https://github.com/BigBadaboom/androidsvg/issues/122
Related Vulnerabilities
CVE-2023-3276 Vulnerability in maven package cn.hutool:hutool-core
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-vertx-http
CVE-2022-0235 Vulnerability in npm package node-fetch
CVE-2016-10735 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap-sass
CVE-2022-31044 Vulnerability in maven package org.rundeck:rundeck