Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: dell

Published: 2019-01-18T00:00:00

Updated: 2023-12-27T15:06:23.165663

Reserved: 2019-01-03T00:00:00


Link: CVE-2019-3773

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-01-18T22:29:01.020

Modified: 2023-12-27T15:15:44.890


Link: CVE-2019-3773

JSON object: View

cve-icon Redhat Information

No data.

CWE