QID 981250
QID 981250: Java (maven) Security Update for org.springframework:spring-core (GHSA-6v7w-535j-rq5m)
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6v7w-535j-rq5m for updates pertaining to this vulnerability.
Vendor References
- GHSA-6v7w-535j-rq5m -
github.com/advisories/GHSA-6v7w-535j-rq5m
CVEs related to QID 981250
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6v7w-535j-rq5m | org.springframework:spring-core |
|