Description
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.
Remediation
References
http://seclists.org/oss-sec/2017/q2/31
http://www.securityfocus.com/bid/97509
Related Vulnerabilities
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-main
CVE-2023-30523 Vulnerability in maven package org.jenkins-ci.plugins:reportportal
CVE-2020-15999 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-1948 Vulnerability in maven package org.apache.dubbo:dubbo-rpc
CVE-2023-37259 Vulnerability in npm package matrix-react-sdk