Description
An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versions are also affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Remediation
References
http://www.openwall.com/lists/oss-security/2022/09/22/1
https://lists.apache.org/thread/02yo04w93rdjmllz4454lvodn5xzhwhl
Related Vulnerabilities
CVE-2021-23436 Vulnerability in npm package immer
CVE-2020-36183 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2019-10319 Vulnerability in maven package org.jenkins-ci.plugins:pam-auth
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport-native-epoll
CVE-2023-38509 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui