Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring MVC's SourceHttpMessageConverter also processed user provided XML and neither disabled XML external entities nor provided an option to disable them. SourceHttpMessageConverter has been modified to provide an option to control the processing of XML external entities and that processing is now disabled by default. It was subsequently discovered that this fix was also incomplete (CVE-2014-0054).
Users of affected versions should apply the following mitigation:
This issue was identified by the Spring development team.
2014-Jan-15: Initial vulnerability report.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy