Description
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Remediation
References
https://pivotal.io/security/cve-2019-3773
https://security.netapp.com/advisory/ntap-20231227-0011/
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/security-alerts/cpujan2021.html
Related Vulnerabilities
CVE-2020-7015 Vulnerability in npm package kibana
CVE-2022-27820 Vulnerability in maven package org.zaproxy:zap
CVE-2023-24057 Vulnerability in maven package org.hl7.fhir.publisher:org.hl7.fhir.publisher.core
CVE-2017-1000113 Vulnerability in maven package org.jenkins-ci.plugins:deploy
CVE-2017-1000504 Vulnerability in maven package org.jenkins-ci.main:jenkins-core