Description
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
Remediation
References
https://github.com/BigBadaboom/androidsvg/issues/122
Related Vulnerabilities
CVE-2022-41255 Vulnerability in maven package org.jenkins-ci.plugins:cons3rt
CVE-2021-28170 Vulnerability in maven package org.glassfish:jakarta.el
CVE-2023-29471 Vulnerability in maven package com.typesafe.akka:akka-stream-kafka
CVE-2017-2602 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-3691 Vulnerability in maven package org.webjars.npm:github-com-layui-layui