Description
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
Remediation
References
https://github.com/pippo-java/pippo/issues/486
Related Vulnerabilities
CVE-2020-7779 Vulnerability in npm package djvalidator
CVE-2020-13410 Vulnerability in npm package aedes
CVE-2023-46499 Vulnerability in npm package @evershop/evershop
CVE-2020-7777 Vulnerability in npm package jsen
CVE-2023-35147 Vulnerability in maven package org.jenkins-ci.plugins:aws-codecommit-trigger