Описание
Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Ссылки
Пакеты
org.springframework.ws:spring-ws
< 2.4.4
2.4.4
org.springframework.ws:spring-ws
>= 3.0.0, <= 3.0.4
3.0.6
org.springframework.ws:spring-xml
< 2.4.4
2.4.4
org.springframework.ws:spring-xml
>= 3.0.0, <= 3.0.4
3.0.6
Связанные уязвимости
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Уязвимость веб-сервисов программной платформы Spring Framework, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность информации