Skip to content
This repository has been archived by the owner on Sep 26, 2024. It is now read-only.

CVE-2019-3774 (Critical) detected in spring-batch-infrastructure-3.0.7.RELEASE.jar #26

Open
mend-bolt-for-github bot opened this issue Jan 30, 2022 · 0 comments
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-bolt-for-github
Copy link

mend-bolt-for-github bot commented Jan 30, 2022

CVE-2019-3774 - Critical Severity Vulnerability

Vulnerable Library - spring-batch-infrastructure-3.0.7.RELEASE.jar

Spring Batch Infrastructure

Library home page: http://spring.io

Path to dependency file: /cap-batch/pom.xml

Path to vulnerable library: /129160510_CTWWRC/downloadResource_LBGVMV/20220129160521/spring-batch-infrastructure-3.0.7.RELEASE.jar

Dependency Hierarchy:

  • spring-batch-infrastructure-3.0.7.RELEASE.jar (Vulnerable Library)

Found in base branch: develop

Vulnerability Details

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Publish Date: 2019-01-15

URL: CVE-2019-3774

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://pivotal.io/security/cve-2019-3774

Release Date: 2019-01-18

Fix Resolution: 3.0.10.RELEASE


Step up your Open Source Security Game with Mend here

@mend-bolt-for-github mend-bolt-for-github bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label Jan 30, 2022
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2019-3774 (High) detected in spring-batch-infrastructure-3.0.7.RELEASE.jar CVE-2019-3774 (Critical) detected in spring-batch-infrastructure-3.0.7.RELEASE.jar Aug 30, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

0 participants