Description
A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax of the file XmlUtil.java of the component XML Parsing Module. The manipulation leads to xml external entity reference. The exploit has been disclosed to the public and may be used. VDB-231626 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Remediation
References
https://fbdhhhh47.github.io/2023/06/06/hutool-XXE/
https://vuldb.com/?ctiid.231626
https://vuldb.com/?id.231626
Related Vulnerabilities
CVE-2021-23337 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2021-21616 Vulnerability in maven package org.biouno:uno-choice
CVE-2018-17960 Vulnerability in maven package org.webjars:ckeditor
CVE-2021-29620 Vulnerability in maven package com.epam.reportportal:service-api
CVE-2022-1295 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js