Description
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
Remediation
References
https://github.com/pippo-java/pippo/issues/486
Related Vulnerabilities
CVE-2022-34115 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2021-39194 Vulnerability in maven package com.charleskorn.kaml:kaml
CVE-2016-10556 Vulnerability in npm package sequelize
CVE-2021-21165 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-csrf-reactive