Description
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Remediation
References
https://github.com/kiegroup/drools/pull/3808
Related Vulnerabilities
CVE-2023-30541 Vulnerability in npm package @openzeppelin/contracts
CVE-2020-15930 Vulnerability in npm package joplin
CVE-2020-2247 Vulnerability in maven package org.jenkins-ci.plugins:klocwork
CVE-2022-43183 Vulnerability in maven package com.xuxueli:xxl-job-core
CVE-2022-0853 Vulnerability in maven package jboss:jboss-client