PT-2017-5780 · Spring+1 · Spring Framework+1
David Jorm
+1
·
Published
2015-05-11
·
Updated
2022-05-13
·
CVE-2014-0225
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Spring Framework versions 3.0.0 through 3.2.8
Spring Framework versions 4.0.0 through 4.0.4
Description:
The issue arises when processing user-provided XML documents, as the Spring Framework did not disable by default the resolution of URI references in a DTD declaration, enabling an XXE attack.
Recommendations:
For Spring Framework versions 3.0.0 through 3.2.8, disable the resolution of URI references in DTD declarations to prevent XXE attacks.
For Spring Framework versions 4.0.0 through 4.0.4, disable the resolution of URI references in DTD declarations to prevent XXE attacks.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Framework
Ubuntu