Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6v7w-535j-rq5m

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Pivotal Spring Framework DoS Attack with XML Input

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

Ссылки

Пакеты

Наименование

org.springframework:spring-web

maven
Затронутые версииВерсия исправления

< 3.2.14

3.2.14

Наименование

org.springframework:spring-web

maven
Затронутые версииВерсия исправления

>= 4.0.0, < 4.1.7

4.1.7

Наименование

org.springframework:spring-web

maven
Затронутые версииВерсия исправления

= 5.0.0.RC2

5.0.0.RC3

EPSS

Процентиль: 79%
0.01378
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.3
redhat
почти 10 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
nvd
почти 9 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
debian
почти 9 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not pro ...

EPSS

Процентиль: 79%
0.01378
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-119