CVE-2019-3772: Spring Integration XML External Entity Injection (XXE)
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-3772?
CVE-2019-3772 is a vulnerability in the Spring Integration (spring-integration-xml and spring-integration-ws modules) software which allows XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
What is the severity of CVE-2019-3772?
The severity of CVE-2019-3772 is critical with a severity score of 9.8 out of 10.
Which versions of Spring Integration are affected by CVE-2019-3772?
Versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions of Spring Integration (spring-integration-xml and spring-integration-ws modules) are affected by CVE-2019-3772.
How can XML External Entity Injection (XXE) be exploited in CVE-2019-3772?
In CVE-2019-3772, XML External Entity Injection (XXE) can be exploited by sending XML data from untrusted sources, which may cause the application to load external entities and disclose internal files or perform server-side request forgery (SSRF) attacks.
Where can I find more information about CVE-2019-3772?
You can find more information about CVE-2019-3772 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/106749), [Pivotal](https://pivotal.io/security/cve-2019-3772), [Oracle](https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html).