All Vulnerability Reports

CVE-2019-3773: XML External Entity Injection (XXE)


Severity

Critical

Description

Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Affected Pivotal Products and Versions

Severity is critical unless otherwise noted.

  • Spring Web Services versions 2.4.3, 3.0.4 and older
Mitigation

Users of affected versions should apply the following mitigation:

  • Upgrade spring-ws, spring-xml jars to 2.4.4, 3.0.6 or later
  • Spring Web Services components that exhibited this vulnerability now disable the features as advised in the reference cheat sheet [1] by default, but allow user configuration of the components if the feature can be enabled because XML is received from a trusted source.
References
History

2019-01-14: Initial vulnerability report published.

Questions?