CVE-2019-3774: XML External Entity Injection (XXE)
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Severity is critical unless otherwise noted.
- Spring Batch versions 3.0.9, 4.0.1, 4.1.0 and older
Users of affected versions should apply the following mitigation:
- Upgrade spring-batch jars to 3.0.10, 4.0.2, 4.1.1 or later
- Spring Batch components that exhibited this vulnerability now disable the features as advised in the reference cheat sheet  by default, but allow user configuration of the components if the feature can be enabled because XML is received from a trusted source.
2019-01-14: Initial vulnerability report published.