Description
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.
Remediation
References
https://svn.apache.org/repos/asf/wink/trunk/security/CVE-2010-2245.pdf
http://marc.info/?l=wink-user&m=127843482925387&w=2
Related Vulnerabilities
CVE-2014-3530 Vulnerability in maven package org.picketlink:picketlink-common
CVE-2023-22579 Vulnerability in npm package @sequelize/core
CVE-2023-2850 Vulnerability in npm package nodebb
CVE-2021-32732 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2023-33962 Vulnerability in maven package io.jstach:jstachio