Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring MVC's Jaxb2RootElementHttpMessageConverter also processed user provided XML and neither disabled XML external entities nor provided an option to disable them. Jaxb2RootElementHttpMessageConverter has been modified to provide an option to control the processing of XML external entities and that processing is now disabled by default.
Users of affected versions should apply the following mitigation:
This issue was reported to the Spring Framework developers by Spase Markovski.
2014-Mar-11: Initial vulnerability report published.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy