Lucene search

K
osvGoogleOSV:GHSA-WR5R-M8PC-85J9
HistoryJan 25, 2019 - 4:18 p.m.

Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml

2019-01-2516:18:49
Google
osv.dev
12

AI Score

9.6

Confidence

High

EPSS

0.005

Percentile

76.9%

Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

AI Score

9.6

Confidence

High

EPSS

0.005

Percentile

76.9%