Description
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
Remediation
References
https://github.com/pippo-java/pippo/issues/486
Related Vulnerabilities
CVE-2022-1233 Vulnerability in maven package org.webjars.bower:urijs
CVE-2023-26486 Vulnerability in maven package org.webjars.npm:vega
CVE-2021-33562 Vulnerability in maven package com.shopizer:shopizer
CVE-2019-15953 Vulnerability in npm package total.js
CVE-2023-43961 Vulnerability in maven package cn.dev33:sa-token-core