Description
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.
Remediation
References
https://svn.apache.org/repos/asf/wink/trunk/security/CVE-2010-2245.pdf
http://marc.info/?l=wink-user&m=127843482925387&w=2
Related Vulnerabilities
CVE-2019-10314 Vulnerability in maven package org.jenkins-ci.plugins:koji
CVE-2020-1929 Vulnerability in maven package org.apache.beam:beam-sdks-java-io-mongodb
CVE-2023-34340 Vulnerability in maven package org.apache.accumulo:accumulo-shell
CVE-2021-39176 Vulnerability in npm package detect-character-encoding
CVE-2022-31160 Vulnerability in maven package org.webjars:jquery-ui