Description
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
Remediation
References
https://github.com/joniles/mpxj/pull/178/commits/c3e457f7a16facfe563eade82b0fa8736a8c96f9
https://www.oracle.com/security-alerts/cpujan2021.html
Related Vulnerabilities
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.enigma2
CVE-2016-4800 Vulnerability in maven package org.eclipse.jetty:jetty-util
CVE-2021-39178 Vulnerability in npm package next
CVE-2018-20677 Vulnerability in maven package org.webjars.npm:bootstrap-sass