Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreWhen processing user provided XML documents, the Spring Framework did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
Spring Framework:
| Fix version | Availability |
|---|---|
| 4.0.5 | OSS |
| 3.2.9 | OSS |
No further mitigation steps are necessary.
This issue was discovered and reported responsibly to the Pivotal security team by Nebula(XIAOBAISHAN,CHIBI,HUBEI.CN) HelloWorld security team, DBappsecurity.com security team. Additional information demonstrating how a full XXE attack could be made was provided by David Jorm of the RedHat security team.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy