Description
A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rups/model/XfaFile.java. The manipulation leads to xml external entity reference. The patch is identified as ac5590925874ef810018a6b60fec216eee54fb32. It is recommended to apply a patch to fix this issue. VDB-217054 is the identifier assigned to this vulnerability.
Remediation
References
https://github.com/itext/rups/commit/ac5590925874ef810018a6b60fec216eee54fb32
https://vuldb.com/?ctiid.217054
https://vuldb.com/?id.217054
Related Vulnerabilities
CVE-2023-25569 Vulnerability in maven package com.ctrip.framework.apollo:apollo
CVE-2021-37695 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2021-32854 Vulnerability in npm package textangular
CVE-2022-31175 Vulnerability in npm package @ckeditor/ckeditor5-markdown-gfm
CVE-2023-47327 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web