Description
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8222-6fc8-mhvf | Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml |
References
History
Fri, 04 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Broadcom
Broadcom spring Web Services |
|
| CPEs | cpe:2.3:a:broadcom:spring_web_services:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pivotal Software
Pivotal Software spring Web Services |
Broadcom
Broadcom spring Web Services |
Tue, 17 Sep 2024 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Spring Web Services XML External Entity Injection (XXE) | Spring Web Services XML External Entity Injection (XXE) |
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T03:33:35.558Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3773
No data.
Status : Modified
Published: 2019-01-18T22:29:01.020
Modified: 2026-09-04T13:45:35.430
Link: CVE-2019-3773
OpenCVE Enrichment
No data.
Github GHSA