Description
bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the Middle or malicious server.
Remediation
References
https://0dd.zone/2018/10/28/bw-calendar-engine-XXE-MitM/
https://github.com/Bedework/bw-calendar-engine/issues/3
Related Vulnerabilities
CVE-2020-6427 Vulnerability in npm package electron
CVE-2019-1010266 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2019-5475 Vulnerability in maven package org.sonatype.nexus.plugins:nexus-yum-repository-plugin
CVE-2021-21639 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-11777 Vulnerability in maven package org.apache.hive:hive-exec