Description
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Remediation
References
https://pivotal.io/security/cve-2019-3773
https://security.netapp.com/advisory/ntap-20231227-0011/
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/security-alerts/cpujan2021.html
Related Vulnerabilities
CVE-2022-28890 Vulnerability in maven package org.apache.jena:jena-core
CVE-2019-16550 Vulnerability in maven package org.jenkins-ci.plugins.m2release:m2release
CVE-2018-1328 Vulnerability in maven package org.apache.zeppelin:zeppelin
CVE-2019-1003024 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk14