Description
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
Remediation
References
https://github.com/traccar/traccar/commit/d7f6c53fd88635885914013649b6807ec53227bf
https://www.traccar.org/blog/
Related Vulnerabilities
CVE-2022-36096 Vulnerability in maven package org.xwiki.platform:xwiki-platform-index-ui
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-mysql-cdc
CVE-2023-26486 Vulnerability in maven package org.webjars.npm:vega-functions
CVE-2021-25912 Vulnerability in npm package dotty
CVE-2022-29567 Vulnerability in maven package com.vaadin:vaadin-grid-flow