QID 980992

QID 980992: Java (maven) Security Update for org.springframework.data:spring-data-commons (GHSA-m929-7fr6-cvjg)

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-m929-7fr6-cvjg for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980992

    Software Advisories
    Advisory ID Software Component Link
    GHSA-m929-7fr6-cvjg org.springframework.data:spring-data-commons URL Logo github.com/advisories/GHSA-m929-7fr6-cvjg