Description
An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function.
Remediation
References
https://github.com/membrane/soa-model/commit/19de16902468e7963cc4dc6b544574bc1ea3f251
https://github.com/membrane/soa-model/commit/3aa295f155f621d5ea661cb9a0604013fc8fd8ff
https://github.com/membrane/soa-model/issues/281
https://github.com/membrane/soa-model/releases/tag/v1.6.4
Related Vulnerabilities
CVE-2022-45685 Vulnerability in maven package org.codehaus.jettison:jettison
CVE-2018-8014 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-beam-sql
CVE-2023-46589 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2011-2204 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core