Description
XXE issue in Airsonic before 10.1.2 during parse.
Remediation
References
https://github.com/airsonic/airsonic/releases/tag/v10.2.1
https://github.com/airsonic/airsonic/blob/master/CHANGELOG.md
Related Vulnerabilities
CVE-2020-2242 Vulnerability in maven package org.jenkins-ci.plugins:database
CVE-2019-0199 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-41184 Vulnerability in maven package org.webjars:jquery-ui
CVE-2020-28469 Vulnerability in npm package glob-parent
CVE-2017-16119 Vulnerability in maven package org.webjars.npm:fresh