[MAVEN:GHSA-M929-7FR6-CVJG] Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

ID
MAVEN:GHSA-M929-7FR6-CVJG
Severity
high
URL
https://github.com/advisories/GHSA-m929-7fr6-cvjg
Published
2018-10-17T17:23:36
(6 years ago)
Modified
2023-01-27T05:02:26
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.springframework.data/spring-data-commons org.springframework.data spring-data-commons >= 2.0.0 < 2.0.7
Fixed pkg:maven/org.springframework.data/spring-data-commons org.springframework.data spring-data-commons = 2.0.7
Affected pkg:maven/org.springframework.data/spring-data-commons org.springframework.data spring-data-commons >= 1.13.0 < 1.13.12
Fixed pkg:maven/org.springframework.data/spring-data-commons org.springframework.data spring-data-commons = 1.13.12
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...