Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreIt was identified that Spring MVC processed user provided XML with JAXB in combination with a StAX XMLInputFactory without disabling external entity resolution. External entity resolution has been disabled in this case. It was subsequently discovered that this fix was incomplete (CVE-2013-6429, CVE-2014-0054).
Users of affected versions should apply the following mitigation:
These issues were identified by Alvaro Munoz of the HP Enterprise Security Team.
2013-Aug-22: Initial vulnerability report published under CVE-2013-4152.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy