VDB
EN
HIGH 8.2

GHSA-2mpf-m756-hxjm

Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource

빠른 조치

GHSA-2mpf-m756-hxjm — org.springframework.ws:spring-xml: 아래 명령으로 수정 버전으로 올리세요.

# pom.xml: bump <version>5.0.2</version> for org.springframework.ws:spring-xml

상세

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML External Entity (XXE) style attacks.

Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Maven / org.springframework.ws:spring-xml
최초 영향 버전: 5.0.0 수정 버전: 5.0.2
수정 # pom.xml: bump <version>5.0.2</version> for org.springframework.ws:spring-xml
Maven / org.springframework.ws:spring-xml
최초 영향 버전: 4.1.0 수정 버전: 4.1.4
수정 # pom.xml: bump <version>4.1.4</version> for org.springframework.ws:spring-xml
Maven / org.springframework.ws:spring-xml
최초 영향 버전: 4.0.0

No fixed version published yet for org.springframework.ws:spring-xml (maven). Pin to a known-safe version or switch to an alternative.

Maven / org.springframework.ws:spring-xml
최초 영향 버전: 3.1.0

No fixed version published yet for org.springframework.ws:spring-xml (maven). Pin to a known-safe version or switch to an alternative.

참고