This advisory has been withdrawn because the underlying vulnerability could not be reproduced. This link is maintained to preserve external references.
An issue in dom4.j org.dom4.io.SAXReader v.2.1.4 and before allows a remote attacker to obtain sensitive information via the setFeature function.
{
"cwe_ids": [
"CWE-776"
],
"github_reviewed": true,
"github_reviewed_at": "2023-10-27T19:50:41Z",
"nvd_published_at": "2023-10-25T18:17:35Z",
"severity": "MODERATE"
}