Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp4p-g69r-438x

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Cross-Site Request Forgery in Spring Framework

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.

Пакеты

Наименование

org.springframework:spring-oxm

maven
Затронутые версииВерсия исправления

<= 3.2.3.RELEASE

3.2.4.RELEASE

EPSS

Процентиль: 99%
0.84056
Высокий

Дефекты

CWE-352

Связанные уязвимости

ubuntu
больше 11 лет назад

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.

redhat
почти 12 лет назад

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.

nvd
больше 11 лет назад

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.

debian
больше 11 лет назад

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, ...

EPSS

Процентиль: 99%
0.84056
Высокий

Дефекты

CWE-352