You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Learn more on MITRE.
Impact
Lily makes use of Cozy's Welcome Channel module, which contains the affected dependency
Patches
In the latest LilyBot version (v4.8.3) we bump our dependency on the welcome channel module to
1.0.1-SNAPSHOT
which contains the fixed versionsWorkarounds
None.
References
QuiltMC/cozy-discord
,GHSA-4725-965f-99mw
)charleskorn/kaml
,GHSA-c24f-2j3g-rg48
)