Description
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
Remediation
References
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0742
Related Vulnerabilities
CVE-2018-1199 Vulnerability in maven package org.springframework.security:spring-security-web
CVE-2014-0073 Vulnerability in npm package cordova-plugin-inappbrowser
CVE-2023-31141 Vulnerability in maven package org.opensearch.plugin:opensearch-security
CVE-2017-4972 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server