The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input.…
apache·CWE-776·Published 2021-01-14