Description
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.
Remediation
References
http://marc.info/?l=wink-user&m=127843482925387&w=2
https://svn.apache.org/repos/asf/wink/trunk/security/CVE-2010-2245.pdf
Related Vulnerabilities
CVE-2021-4307 Vulnerability in npm package baobab
CVE-2019-20174 Vulnerability in maven package org.webjars.npm:auth0-lock
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty.ee10:jetty-ee10-servlets
CVE-2021-43783 Vulnerability in npm package @backstage/plugin-scaffolder-backend
CVE-2020-9483 Vulnerability in maven package org.apache.skywalking:server-storage-plugin