GHSA-wr5r-m8pc-85j9
LOWCVE-2019-3772Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
- Affected
- >= 5.0.0, < 5.0.11, < 4.3.19, >= 5.1.0, < 5.1.2
- Fixed in
- 5.0.11
- Weakness
- CWE-611
- Published
- 2019-01-25
- Source
- github