← back
CVE-2019-3772

Spring Integration XML External Entity Injection (XXE)

EPSS 3.0%CWE-611
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →