[MAVEN:GHSA-F93F-G33R-8PCP] Improper Restriction of XML External Entity Reference in Spring Framework

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

Package Affected Version
pkg:maven/org.springframework/spring-webmvc >= 3.0.0, < 3.2.8
pkg:maven/org.springframework/spring-webmvc >= 4.0.0, < 4.0.5
ID
MAVEN:GHSA-F93F-G33R-8PCP
Severity
high
URL
https://github.com/advisories/GHSA-f93f-g33r-8pcp
Published
2022-05-13T01:02:39
(2 years ago)
Modified
2023-01-27T05:02:11
(20 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.springframework/spring-webmvc org.springframework spring-webmvc >= 3.0.0 < 3.2.8
Fixed pkg:maven/org.springframework/spring-webmvc org.springframework spring-webmvc = 3.2.8
Affected pkg:maven/org.springframework/spring-webmvc org.springframework spring-webmvc >= 4.0.0 < 4.0.5
Fixed pkg:maven/org.springframework/spring-webmvc org.springframework spring-webmvc = 4.0.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...