Description
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem, perform same-site-request-forgery (SSRF), port-scanning behind the firewall or DoS the application.
Remediation
References
http://www.securityfocus.com/bid/99873
https://lists.apache.org/thread.html/b72c3a511592ec70729b3ec2d29302b6ce87bbeab62d4745617a6bd0%40%3Cdev.sling.apache.org%3E
Related Vulnerabilities
CVE-2018-14042 Vulnerability in maven package org.webjars:bootstrap-sass
CVE-2023-31890 Vulnerability in maven package com.glazedlists:glazedlists
CVE-2011-2487 Vulnerability in maven package org.apache.ws.security:wss4j
CVE-2023-46234 Vulnerability in npm package browserify-sign
CVE-2020-2281 Vulnerability in maven package org.6wind.jenkins:lockable-resources