Description
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Remediation
References
https://github.com/kiegroup/drools/pull/3808
Related Vulnerabilities
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport-native-epoll
CVE-2011-2481 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-37947 Vulnerability in maven package org.openshift.jenkins:openshift-login