An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://lists.debian.org/debian-lts-announce/2021/07/msg00012.html
https://lists.debian.org/debian-lts-announce/2021/06/msg00026.html
https://github.com/hunterhacker/jdom/releases