Description
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
Remediation
References
https://github.com/traccar/traccar/commit/d7f6c53fd88635885914013649b6807ec53227bf
https://www.traccar.org/blog/
Related Vulnerabilities
CVE-2022-20612 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2021-39176 Vulnerability in npm package detect-character-encoding
CVE-2020-5259 Vulnerability in maven package org.webjars.bower:dojox
CVE-2022-45398 Vulnerability in maven package org.zeroturnaround:cluster-stats
CVE-2023-22461 Vulnerability in npm package @mattkrick/sanitize-svg