Description
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Remediation
References
https://pivotal.io/security/cve-2019-3773
https://security.netapp.com/advisory/ntap-20231227-0011/
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/security-alerts/cpujan2021.html
Related Vulnerabilities
CVE-2021-27290 Vulnerability in maven package org.webjars.npm:ssri
CVE-2022-45385 Vulnerability in maven package org.jenkins-ci.plugins:dockerhub-notification
CVE-2022-31197 Vulnerability in maven package org.postgresql:postgresql
CVE-2018-1999042 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2024-22207 Vulnerability in npm package @fastify/swagger-ui