PT-2019-5717 · Spring · Spring Web Services

Published

2019-01-18

·

Updated

2023-12-27

·

CVE-2019-3773

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spring Web Services versions 2.4.3, 3.0.4, and older unsupported versions
Description The issue is related to incorrect restriction of XML links to external objects, which can lead to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. This can allow a remote attacker to impact the confidentiality, integrity, and availability of information.
Recommendations For versions 2.4.3 and 3.0.4, update to a version that includes a fix for the XML External Entity Injection issue. For older unsupported versions, consider upgrading to a supported version that includes the necessary security fixes. As a temporary workaround, consider restricting the reception of XML data from untrusted sources to minimize the risk of exploitation.

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2021-00727
CVE-2019-3773
GHSA-8222-6FC8-MHVF

Affected Products

Spring Web Services