CVE-2019-3778: Open Redirector in spring-security-oauth2

CRITICAL | FEBRUARY 21, 2019 | CVE-2019-3778
Description Affected Spring Products and Versions Mitigation Credit This issue was identified and responsibly reported by Dirk Koehler (github.com/phrinx) from dotloop. Special thanks to Macchinetta Framework Development Team from NTT, NTT Comware, NTT DATA…

CVE-2019-3773: XML External Entity Injection (XXE)

CRITICAL | JANUARY 14, 2019 | CVE-2019-3773
Description Affected Spring Products and Versions Mitigation References https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Prevention_Cheat_Sheet History 2019-01-14: Initial vulnerability report published.

CVE-2019-3772: XML External Entity Injection (XXE)

CRITICAL | JANUARY 14, 2019 | CVE-2019-3772
Description Affected Spring Products and Versions Mitigation References https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Prevention_Cheat_Sheet History 2019-01-14: Initial vulnerability report published.

CVE-2019-3774: XML External Entity Injection (XXE)

CRITICAL | JANUARY 14, 2019 | CVE-2019-3774
Description Affected Spring Products and Versions Mitigation References https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Prevention_Cheat_Sheet History 2019-01-14: Initial vulnerability report published.