Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreWhen processing user provided XML documents, the Spring Framework did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
Users of affected versions should apply the following mitigation:
This issue was discovered and reported responsibly to the Pivotal security team by Nebula(XIAOBAISHAN,CHIBI,HUBEI.CN) HelloWorld security team, DBappsecurity.com security team. Additional information demonstrating how a full XXE attack could be made was provided by David Jorm of the RedHat security team.
2014-May-28: Initial vulnerability report published.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy