Description
Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/servlet/common/MethodBase.java and webdav/servlet/common/PostRequestPars.java.
Remediation
References
https://github.com/Bedework/bw-webdav/pull/1
https://github.com/Bedework/bw-webdav/compare/bw-webdav-4.0.2...bw-webdav-4.0.3
Related Vulnerabilities
CVE-2013-4444 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2014-2059 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2017-5954 Vulnerability in npm package serialize-to-js
CVE-2020-12265 Vulnerability in maven package org.webjars:decompress
CVE-2021-43307 Vulnerability in maven package org.webjars.npm:semver-regex