Improper Restriction of XML External Entity Reference in pippo-core
Critical severity
GitHub Reviewed
Published
Dec 19, 2018
to the GitHub Advisory Database
•
Updated Mar 4, 2024
Description
Published to the GitHub Advisory Database
Dec 19, 2018
Reviewed
Jun 16, 2020
Last updated
Mar 4, 2024
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
References