GHSA-2mpf-m756-hxjm
Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource
빠른 조치
GHSA-2mpf-m756-hxjm — org.springframework.ws:spring-xml: 아래 명령으로 수정 버전으로 올리세요.
# pom.xml: bump <version>5.0.2</version> for org.springframework.ws:spring-xml 상세
Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML External Entity (XXE) style attacks.
Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
5.0.0 수정 버전: 5.0.2 # pom.xml: bump <version>5.0.2</version> for org.springframework.ws:spring-xml 4.1.0 수정 버전: 4.1.4 # pom.xml: bump <version>4.1.4</version> for org.springframework.ws:spring-xml 4.0.0 No fixed version published yet for org.springframework.ws:spring-xml (maven). Pin to a known-safe version or switch to an alternative.
3.1.0 No fixed version published yet for org.springframework.ws:spring-xml (maven). Pin to a known-safe version or switch to an alternative.