CVE-2019-3774
18.01.2019, 22:29
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.Enginsight
Vendor | Product | Version |
---|---|---|
pivotal_software | spring_batch | 𝑥 ≤ 3.0.9 |
pivotal_software | spring_batch | 4.0.0 ≤ 𝑥 ≤ 4.0.1 |
pivotal_software | spring_batch | 4.1.0 |
𝑥
= Vulnerable software versions
References