Description
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.
Remediation
References
http://marc.info/?l=wink-user&m=127843482925387&w=2
https://svn.apache.org/repos/asf/wink/trunk/security/CVE-2010-2245.pdf
Related Vulnerabilities
CVE-2021-31412 Vulnerability in maven package com.vaadin:flow-server
CVE-2021-30638 Vulnerability in maven package org.apache.tapestry:tapestry-core
CVE-2022-43425 Vulnerability in maven package io.jenkins.plugins:custom-checkbox-parameter
CVE-2018-14041 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap
CVE-2020-28472 Vulnerability in maven package org.webjars.bower:aws-sdk