Description
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3731 | When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack. |
Github GHSA |
GHSA-f93f-g33r-8pcp | Improper Restriction of XML External Entity Reference in Spring Framework |
Ubuntu USN |
USN-4774-1 | Spring Framework vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-08-06T09:05:39.298Z
Reserved: 2013-12-03T00:00:00.000Z
Link: CVE-2014-0225
No data.
Status : Modified
Published: 2017-05-25T17:29:00.207
Modified: 2026-05-13T00:24:29.033
Link: CVE-2014-0225
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN