Description
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
Remediation
References
https://github.com/pippo-java/pippo/issues/486
Related Vulnerabilities
CVE-2022-45690 Vulnerability in maven package cn.hutool:hutool-json
CVE-2022-25890 Vulnerability in npm package wifey
CVE-2022-35948 Vulnerability in maven package org.webjars.npm:undici
CVE-2022-0671 Vulnerability in maven package org.eclipse.lemminx:lemminx-parent
CVE-2023-46660 Vulnerability in maven package org.jenkins-ci.plugins:zanata