Description
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Remediation
References
https://github.com/kiegroup/drools/pull/3808
Related Vulnerabilities
CVE-2020-19698 Vulnerability in maven package org.webjars.npm:editor.md
CVE-2011-2093 Vulnerability in maven package com.adobe.blazeds:flex-messaging-core
CVE-2021-26275 Vulnerability in npm package eslint-fixer
CVE-2019-0205 Vulnerability in maven package org.apache.thrift:libthrift
CVE-2019-17495 Vulnerability in maven package org.webjars.bower:swagger-ui