Description
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0197 | Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. |
Github GHSA |
GHSA-wr5r-m8pc-85j9 | Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml |
References
History
Mon, 16 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Spring Integration XML External Entity Injection (XXE) | Spring Integration XML External Entity Injection (XXE) |
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T16:23:25.840Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3772
No data.
Status : Modified
Published: 2019-01-18T22:29:00.973
Modified: 2024-11-21T04:42:29.987
Link: CVE-2019-3772
OpenCVE Enrichment
No data.
EUVD
Github GHSA