QID 982262
QID 982262: Java (maven) Security Update for org.springframework.ws:spring-xml (GHSA-8222-6fc8-mhvf)
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8222-6fc8-mhvf for updates pertaining to this vulnerability.
Vendor References
- GHSA-8222-6fc8-mhvf -
github.com/advisories/GHSA-8222-6fc8-mhvf
CVEs related to QID 982262
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8222-6fc8-mhvf | org.springframework.ws:spring-ws |
|
|
| GHSA-8222-6fc8-mhvf | org.springframework.ws:spring-xml |
|