When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
References
Link Resource
https://pivotal.io/security/cve-2014-0225 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: dell

Published: 2017-05-25T17:00:00

Updated: 2017-05-25T16:57:01

Reserved: 2013-12-03T00:00:00


Link: CVE-2014-0225

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-05-25T17:29:00.207

Modified: 2022-04-11T17:16:26.983


Link: CVE-2014-0225

JSON object: View

cve-icon Redhat Information

No data.

CWE