Description
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
Remediation
References
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0742
Related Vulnerabilities
CVE-2014-0229 Vulnerability in maven package org.apache.hadoop:hadoop-hdfs
CVE-2021-45029 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2017-12647 Vulnerability in maven package com.liferay:com.liferay.knowledge.base.service
CVE-2023-29524 Vulnerability in maven package org.xwiki.platform:xwiki-platform-scheduler-ui
CVE-2023-35149 Vulnerability in maven package org.jenkins-ci.plugins:ease-plugin