Description
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Remediation
References
https://github.com/kiegroup/drools/pull/3808
Related Vulnerabilities
CVE-2019-13235 Vulnerability in maven package org.opencms:opencms-core
CVE-2021-23594 Vulnerability in npm package realms-shim
CVE-2021-32860 Vulnerability in npm package izimodal
CVE-2021-22137 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2018-14042 Vulnerability in maven package org.webjars.bower:bootstrap-sass