PT-2017-5780 · Spring+1 · Spring Framework+1

David Jorm

+1

·

Publicado

2015-05-11

·

Atualizado

2022-05-13

·

CVE-2014-0225

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Spring Framework versions 3.0.0 through 3.2.8 Spring Framework versions 4.0.0 through 4.0.4
Description: The issue arises when processing user-provided XML documents, as the Spring Framework did not disable by default the resolution of URI references in a DTD declaration, enabling an XXE attack.
Recommendations: For Spring Framework versions 3.0.0 through 3.2.8, disable the resolution of URI references in DTD declarations to prevent XXE attacks. For Spring Framework versions 4.0.0 through 4.0.4, disable the resolution of URI references in DTD declarations to prevent XXE attacks.

Exploit

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0225
GHSA-F93F-G33R-8PCP
MGASA-2015-0211
USN-4774-1

Produtos afetados

Spring Framework
Ubuntu