Description
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Remediation
References
https://github.com/kiegroup/drools/pull/3808
Related Vulnerabilities
CVE-2020-28503 Vulnerability in npm package copy-props
CVE-2021-23448 Vulnerability in npm package config-handler
CVE-2018-1000118 Vulnerability in maven package org.webjars.npm:electron
CVE-2015-8855 Vulnerability in npm package semver
CVE-2021-37580 Vulnerability in maven package org.apache.shenyu:shenyu-admin