Description
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
Remediation
References
https://github.com/stanfordnlp/corenlp/commit/1f52136321cfca68b991bd7870563d06cf96624d
https://huntr.dev/bounties/3d7e70fe-dddd-4b79-af62-8e058c4d5763
Related Vulnerabilities
CVE-2020-7771 Vulnerability in npm package asciitable.js
CVE-2021-41038 Vulnerability in npm package @theia/plugin-ext
CVE-2022-26112 Vulnerability in maven package org.apache.pinot:pinot-spi
CVE-2022-34662 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api
CVE-2017-12617 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core