An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
{ "cpes": [ "cpe:2.3:a:apache:solr:8.8.1:*:*:*:*:*:*:*", "cpe:2.3:a:apache:solr:8.9:*:*:*:*:*:*:*" ], "severity": "High" }