When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
2017-05-25T17:29:00.207
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | pivotal_software | spring_framework | 3.0.0 | Yes |
| Application | pivotal_software | spring_framework | 3.1.0 | Yes |
| Application | pivotal_software | spring_framework | 3.2.0 | Yes |
| Application | pivotal_software | spring_framework | 4.0.0 | Yes |
| Application | vmware | spring_framework | 3.0.1 | Yes |
| Application | vmware | spring_framework | 3.0.2 | Yes |
| Application | vmware | spring_framework | 3.0.3 | Yes |
| Application | vmware | spring_framework | 3.0.4 | Yes |
| Application | vmware | spring_framework | 3.0.5 | Yes |
| Application | vmware | spring_framework | 3.0.6 | Yes |
| Application | vmware | spring_framework | 3.0.7 | Yes |
| Application | vmware | spring_framework | 3.1.0 | Yes |
| Application | vmware | spring_framework | 3.1.0 | Yes |
| Application | vmware | spring_framework | 3.1.1 | Yes |
| Application | vmware | spring_framework | 3.1.2 | Yes |
| Application | vmware | spring_framework | 3.1.3 | Yes |
| Application | vmware | spring_framework | 3.1.4 | Yes |
| Application | vmware | spring_framework | 3.2.0 | Yes |
| Application | vmware | spring_framework | 3.2.0 | Yes |
| Application | vmware | spring_framework | 3.2.0 | Yes |
| Application | vmware | spring_framework | 3.2.1 | Yes |
| Application | vmware | spring_framework | 3.2.2 | Yes |
| Application | vmware | spring_framework | 3.2.3 | Yes |
| Application | vmware | spring_framework | 3.2.4 | Yes |
| Application | vmware | spring_framework | 3.2.5 | Yes |
| Application | vmware | spring_framework | 3.2.6 | Yes |
| Application | vmware | spring_framework | 3.2.7 | Yes |
| Application | vmware | spring_framework | 3.2.8 | Yes |
| Application | vmware | spring_framework | 4.0.0 | Yes |
| Application | vmware | spring_framework | 4.0.0 | Yes |
| Application | vmware | spring_framework | 4.0.1 | Yes |
| Application | vmware | spring_framework | 4.0.2 | Yes |
| Application | vmware | spring_framework | 4.0.3 | Yes |
| Application | vmware | spring_framework | 4.0.4 | Yes |