Description
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
Remediation
References
https://github.com/traccar/traccar/commit/d7f6c53fd88635885914013649b6807ec53227bf
https://www.traccar.org/blog/
Related Vulnerabilities
CVE-2020-16040 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-23305 Vulnerability in maven package log4j:log4j
CVE-2019-13236 Vulnerability in maven package org.opencms:opencms-core
CVE-2016-0762 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2023-30525 Vulnerability in maven package org.jenkins-ci.plugins:reportportal