Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring MVC's SourceHttpMessageConverter also processed user provided XML and neither disabled XML external entities nor provided an option to disable them. SourceHttpMessageConverter has been modified to provide an option to control the processing of XML external entities and that processing is now disabled by default. It was subsequently discovered that this fix was also incomplete (CVE-2014-0054).
Spring Framework:
| Fix version | Availability |
|---|---|
| 3.2.5 | OSS |
No further mitigation steps are necessary.
This issue was identified by the Spring development team.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy