Description
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
Remediation
References
https://github.com/traccar/traccar/commit/d7f6c53fd88635885914013649b6807ec53227bf
https://www.traccar.org/blog/
Related Vulnerabilities
CVE-2019-5423 Vulnerability in npm package http-live-simulator
CVE-2020-7736 Vulnerability in npm package bmoor
CVE-2021-32822 Vulnerability in npm package hbs
CVE-2021-44906 Vulnerability in maven package org.webjars.bowergithub.substack:minimist
CVE-2019-10744 Vulnerability in maven package org.webjars.bower:lodash