Description
Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java.
Remediation
References
https://github.com/azkaban/azkaban/issues/2478
Related Vulnerabilities
CVE-2022-25869 Vulnerability in maven package org.webjars.npm:angular
CVE-2020-9281 Vulnerability in npm package ckeditor4-dev
CVE-2018-1000616 Vulnerability in maven package org.onosproject:onos-cli
CVE-2014-0050 Vulnerability in maven package commons-fileupload:commons-fileupload
CVE-2023-31826 Vulnerability in maven package org.skyscreamer:nevado-jms