In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15232.json"