Vendor
Copernik XML Factory versions prior to 0.1.2 fail to restrict XInclude resource resolution when using the stock JDK provider, enabling local file disclosure or SSRF via malicious XML inputs.