GHSA-f93f-g33r-8pcp
Dashboard / Vulnerabilities / GHSA-f93f-g33r-8pcp
Summary: Improper Restriction of XML External Entity Reference in Spring Framework
Details: When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
References: https://nvd.nist.gov/vuln/detail/CVE-2014-0225, https://github.com/spring-projects/spring-framework/commit/44ee51a6c9c3734b3fcf9a20817117e86047d753, https://github.com/spring-projects/spring-framework/commit/8e096aeef55287dc829484996c9330cf755891a1, https://github.com/spring-projects/spring-framework/commit/c6503ebbf7c9e21ff022c58706dbac5417b2b5eb, https://jira.spring.io/browse/SPR-11768, https://pivotal.io/security/cve-2014-0225
Affected packages
Package
Name: org.springframework:spring-webmvc
Purl: pkg:maven/org.springframework/spring-webmvc
Affected ranges
Type: ECOSYSTEM
Events:
