PT-2017-5780 · Spring+1 · Spring Framework+1

David Jorm

+1

·

Published

2015-05-11

·

Updated

2022-05-13

·

CVE-2014-0225

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Spring Framework versions 3.0.0 through 3.2.8 Spring Framework versions 4.0.0 through 4.0.4
Description: The issue arises when processing user-provided XML documents, as the Spring Framework did not disable by default the resolution of URI references in a DTD declaration, enabling an XXE attack.
Recommendations: For Spring Framework versions 3.0.0 through 3.2.8, disable the resolution of URI references in DTD declarations to prevent XXE attacks. For Spring Framework versions 4.0.0 through 4.0.4, disable the resolution of URI references in DTD declarations to prevent XXE attacks.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0225
GHSA-F93F-G33R-8PCP
MGASA-2015-0211
USN-4774-1

Affected Products

Spring Framework
Ubuntu