This repository has been archived by the owner on Sep 26, 2024. It is now read-only.
CVE-2019-3774 (Critical) detected in spring-batch-infrastructure-3.0.7.RELEASE.jar #26
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2019-3774 - Critical Severity Vulnerability
Vulnerable Library - spring-batch-infrastructure-3.0.7.RELEASE.jar
Spring Batch Infrastructure
Library home page: http://spring.io
Path to dependency file: /cap-batch/pom.xml
Path to vulnerable library: /129160510_CTWWRC/downloadResource_LBGVMV/20220129160521/spring-batch-infrastructure-3.0.7.RELEASE.jar
Dependency Hierarchy:
Found in base branch: develop
Vulnerability Details
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Publish Date: 2019-01-15
URL: CVE-2019-3774
CVSS 3 Score Details (9.8)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://pivotal.io/security/cve-2019-3774
Release Date: 2019-01-18
Fix Resolution: 3.0.10.RELEASE
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: