In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"64744398024010156530414990151867324035",
"103094106067725634274456181224152056068",
"137370831289664590268145846107581954716",
"290240703078587816964598778996448964437",
"101689998601590319437863611412017325679"
]
},
"source": "https://github.com/traccar/traccar/commit/d7f6c53fd88635885914013649b6807ec53227bf",
"id": "CVE-2019-5748-bd546df7",
"signature_version": "v1",
"target": {
"file": "src/org/traccar/protocol/SpotProtocolDecoder.java"
},
"signature_type": "Line",
"deprecated": false
},
{
"digest": {
"function_hash": "244839823815014023820227176207891796806",
"length": 346.0
},
"source": "https://github.com/traccar/traccar/commit/d7f6c53fd88635885914013649b6807ec53227bf",
"id": "CVE-2019-5748-e794ca27",
"signature_version": "v1",
"target": {
"file": "src/org/traccar/protocol/SpotProtocolDecoder.java",
"function": "SpotProtocolDecoder"
},
"signature_type": "Function",
"deprecated": false
}
]