Description
bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the Middle or malicious server.
Remediation
References
https://0dd.zone/2018/10/28/bw-calendar-engine-XXE-MitM/
https://github.com/Bedework/bw-calendar-engine/issues/3
Related Vulnerabilities
CVE-2022-0748 Vulnerability in npm package post-loader
CVE-2020-7622 Vulnerability in maven package io.jooby:jooby-netty
CVE-2022-25167 Vulnerability in maven package org.apache.flume:flume-parent
CVE-2016-6796 Vulnerability in maven package org.apache.tomcat:jasper
CVE-2021-22144 Vulnerability in maven package org.elasticsearch:elasticsearch