spring-xml is vulnerable to XML External Entity (XXE) Attack
80
High Risk
Spring Web Services contains an XML External Entity (XXE) vulnerability in Jaxp13XPathTemplate when evaluating XPath expressions against StreamSource or SAXSource inputs. Due to the use of an XML parser configuration that does not apply Spring's hardened settings, applications processing untrusted XML may allow attackers to resolve external entities. Successful exploitation can result in sensitive file disclosure, server-side request forgery, or other impacts depending on the environment and parser configuration.
You are affected if you are using a version that falls within the vulnerable range.
spring-xml is vulnerable to XML External Entity (XXE) Attack in versions 0.0.1 - 3.1.8, 4.0.0 - 4.0.18, 4.1.0 - 4.1.3 and 5.0.0 - 5.0.1.
Upgrade the org.springframework.ws:spring-xml library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant