Description
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
Remediation
References
https://github.com/pippo-java/pippo/issues/486
Related Vulnerabilities
CVE-2014-0074 Vulnerability in maven package org.apache.shiro:shiro-core
CVE-2017-16180 Vulnerability in npm package serverabc
CVE-2022-39353 Vulnerability in maven package org.webjars.npm:xmldom__xmldom
CVE-2022-24377 Vulnerability in npm package cycle-import-check
CVE-2018-16330 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md