Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13239
HistoryJan 16, 2019 - 6:32 a.m.

XML External Entity Injection (XXE)

2019-01-1606:32:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.005

Percentile

76.9%

Spring Integration is vulnerable to XML external entity injection (XXE). The library does not filter malicious XML data input due to failing to disable the Document Type Definition External Entities by default.

EPSS

0.005

Percentile

76.9%