logo

CVE-2014-0225 org.springframework:spring-webmvc

Package

Manager: maven
Name: org.springframework:spring-webmvc
Vulnerable Version: >=4.0.0 <4.0.5 || >=3.0.0 <3.2.8

Severity

Level: High

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00231 pctl0.45867

Details

Improper Restriction of XML External Entity Reference in Spring Framework When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

Metadata

Created: 2022-05-13T01:02:39Z
Modified: 2024-02-27T23:55:20Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f93f-g33r-8pcp/GHSA-f93f-g33r-8pcp.json
CWE IDs: ["CWE-611"]
Alternative ID: GHSA-f93f-g33r-8pcp
Finding: F083
Auto approve: 1