Description
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.
Remediation
References
http://seclists.org/oss-sec/2017/q2/31
http://www.securityfocus.com/bid/97509
Related Vulnerabilities
CVE-2020-27219 Vulnerability in maven package org.eclipse.hawkbit:hawkbit-update-server
CVE-2020-15500 Vulnerability in maven package org.webjars.npm:tileserver-gl
CVE-2021-3690 Vulnerability in maven package io.undertow:undertow-core
CVE-2021-43138 Vulnerability in maven package org.webjars.bower:async
CVE-2020-6449 Vulnerability in maven package org.webjars.npm:electron