Description
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
Remediation
References
https://github.com/BigBadaboom/androidsvg/issues/122
Related Vulnerabilities
CVE-2020-2213 Vulnerability in maven package org.jenkins-ci.plugins:whitesource
CVE-2018-1999033 Vulnerability in maven package org.jenkins-ci.plugins:anchore-container-scanner
CVE-2019-1003032 Vulnerability in maven package org.jenkins-ci.plugins:email-ext
CVE-2020-28477 Vulnerability in maven package org.webjars.npm:immer