Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml
Critical severity
GitHub Reviewed
Published
Jan 25, 2019
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jan 18, 2019
Published to the GitHub Advisory Database
Jan 25, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 27, 2023
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
References