spring-ws-core is vulnerable to Server-side Request Forgery (SSRF)
86
High Risk
Spring WS contains a server-side request forgery (SSRF) vulnerability when processing WS-Addressing ReplyTo and FaultTo headers. Applications that accept WS-Addressing headers from untrusted sources and use out-of-band replies may initiate outbound connections to attacker-controlled destinations without validating their safety. An attacker can exploit this behavior to force the application to connect to internal systems, cloud metadata services, or other restricted network resources.
You are affected if using a vulnerable version.
spring-ws-core is vulnerable to Server-side Request Forgery (SSRF) in versions 0.0.1 - 3.1.8, 4.0.0 - 4.0.18, 4.1.0 - 4.1.3 and 5.0.0 - 5.0.1.
Upgrade the org.springframework.ws:spring-ws-core library to the patch version. If you cannot upgrade, you can restrict the destinations that each configured sender accepts by overriding its supports method.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant