Description
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
Remediation
References
https://github.com/traccar/traccar/commit/d7f6c53fd88635885914013649b6807ec53227bf
https://www.traccar.org/blog/
Related Vulnerabilities
CVE-2021-23443 Vulnerability in npm package edge.js
CVE-2016-4055 Vulnerability in maven package org.fujion.webjars:moment
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty.http2:http2-hpack
CVE-2021-41580 Vulnerability in npm package passport-oauth2
CVE-2022-41252 Vulnerability in maven package org.jenkins-ci.plugins:cons3rt