Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Users of affected versions should apply the following mitigation:
2019-01-14: Initial vulnerability report published.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy