GHSA-8222-6fc8-mhvf
CRITICALCVE-2019-3773Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
- Affected
- >= 3.0.0, <= 3.0.4, < 2.4.4
- Fixed in
- 3.0.6
- Weakness
- CWE-611
- Published
- 2019-01-25
- Source
- github