Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0225

Опубликовано: 25 мая 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.8

Описание

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

3.0.6.RELEASE-14
cosmic

not-affected

3.0.6.RELEASE-14
devel

not-affected

3.0.6.RELEASE-14
disco

not-affected

3.0.6.RELEASE-14
eoan

not-affected

3.0.6.RELEASE-14
esm-apps/bionic

not-affected

3.0.6.RELEASE-14
esm-apps/focal

not-affected

3.0.6.RELEASE-14
esm-apps/jammy

not-affected

3.0.6.RELEASE-14
esm-apps/xenial

not-affected

3.0.6.RELEASE-14

Показывать по

EPSS

Процентиль: 52%
0.00291
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

redhat
около 11 лет назад

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS3: 8.8
nvd
около 8 лет назад

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

CVSS3: 8.8
debian
около 8 лет назад

When processing user provided XML documents, the Spring Framework 4.0. ...

CVSS3: 8.8
github
около 3 лет назад

Improper Restriction of XML External Entity Reference in Spring Framework

EPSS

Процентиль: 52%
0.00291
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3