QID 980992
QID 980992: Java (maven) Security Update for org.springframework.data:spring-data-commons (GHSA-m929-7fr6-cvjg)
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-m929-7fr6-cvjg for updates pertaining to this vulnerability.
Vendor References
- GHSA-m929-7fr6-cvjg -
github.com/advisories/GHSA-m929-7fr6-cvjg
CVEs related to QID 980992
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m929-7fr6-cvjg | org.springframework.data:spring-data-commons |
|