Description
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
Remediation
References
https://github.com/traccar/traccar/commit/d7f6c53fd88635885914013649b6807ec53227bf
https://www.traccar.org/blog/
Related Vulnerabilities
CVE-2023-44487 Vulnerability in maven package org.eclipse.jetty.http2:http2-common
CVE-2022-23647 Vulnerability in npm package prismjs
CVE-2020-17530 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2011-5245 Vulnerability in maven package org.jboss.resteasy:resteasy-jaxrs
CVE-2023-46502 Vulnerability in maven package org.opencrx:opencrx-core