CVE-2019-3774: XML External Entity Injection (XXE)

CRITICAL | JANUARY 14, 2019 | CVE-2019-3774

Description

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Affected Spring Products and Versions

  • Spring Batch versions 3.0.9, 4.0.1, 4.1.0 and older

Mitigation

Users of affected versions should apply the following mitigation:

  • Upgrade spring-batch jars to 3.0.10, 4.0.2, 4.1.1 or later
  • Spring Batch components that exhibited this vulnerability now disable the features as advised in the reference cheat sheet [1] by default, but allow user configuration of the components if the feature can be enabled because XML is received from a trusted source.

References

History

2019-01-14: Initial vulnerability report published.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all