Description
Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java.
Remediation
References
https://github.com/azkaban/azkaban/issues/2478
Related Vulnerabilities
CVE-2022-36157 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2021-21627 Vulnerability in maven package org.jenkins-ci.plugins:libvirt-slave
CVE-2022-4348 Vulnerability in maven package com.ruoyi:ruoyi-common
CVE-2023-46660 Vulnerability in maven package org.jenkins-ci.plugins:zanata
CVE-2022-43410 Vulnerability in maven package org.jenkins-ci.plugins:mercurial