CVE Database
/

CVE-2014-0225

Back to search

CVE-2014-0225

Published: May 25, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

VendorProductVersions

Pivotal

Spring Framework

affected
4.0.0 to 4.0.4
affected
3.0.0 to 3.2.8
affected
Earlier unsupported versions may be affected

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now