In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.mapfish.print:print-lib(Maven) | 3.0 | 3.24 | N/A |
| org.mapfish.print:print-servlet(Maven) | 3.0 | 3.24 | N/A |
| org.mapfish.print:print-standalone(Maven) | 3.0 | 3.24 | N/A |
CVSS Metrics