Loading HuntDB...

GHSA-f93f-g33r-8pcp

GitHub Security Advisory

Improper Restriction of XML External Entity Reference in Spring Framework

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

Affected Packages

Maven org.springframework:spring-webmvc
Affected versions: 4.0.0 (fixed in 4.0.5)
Maven org.springframework:spring-webmvc
Affected versions: 3.0.0 (fixed in 3.2.8)

Related CVEs

Key Information

GHSA ID
GHSA-f93f-g33r-8pcp
Published
May 13, 2022 1:02 AM
Last Modified
February 27, 2024 11:55 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.springframework:spring-webmvc
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 5, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.