Description
In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.
Remediation
References
http://www.securityfocus.com/bid/107844
https://bugs.eclipse.org/bugs/show_bug.cgi?id=545835
Related Vulnerabilities
CVE-2017-1000092 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2018-1000125 Vulnerability in maven package com.inversoft:prime-jwt
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap-sass
CVE-2022-24377 Vulnerability in npm package cycle-import-check
CVE-2018-1999002 Vulnerability in maven package org.jenkins-ci.main:jenkins-core