Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-0225

Опубликовано: 25 мая 2017
Источник: debian
EPSS Низкий

Описание

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libspring-javafixed3.0.6.RELEASE-14package
libspring-javano-dsasqueezepackage
libspring-javano-dsawheezypackage

EPSS

Процентиль: 46%
0.00236
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 9 лет назад

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

redhat
почти 12 лет назад

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS3: 8.8
nvd
почти 9 лет назад

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS3: 8.8
github
почти 4 года назад

Improper Restriction of XML External Entity Reference in Spring Framework

EPSS

Процентиль: 46%
0.00236
Низкий