Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f93f-g33r-8pcp

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Improper Restriction of XML External Entity Reference in Spring Framework

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

Пакеты

Наименование

org.springframework:spring-webmvc

maven
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.5

4.0.5

Наименование

org.springframework:spring-webmvc

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.2.8

3.2.8

EPSS

Процентиль: 52%
0.00291
Низкий

8.8 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 8 лет назад

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

redhat
около 11 лет назад

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS3: 8.8
nvd
около 8 лет назад

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS3: 8.8
debian
около 8 лет назад

When processing user provided XML documents, the Spring Framework 4.0. ...

EPSS

Процентиль: 52%
0.00291
Низкий

8.8 High

CVSS3

Дефекты

CWE-611