CVE-2019-3774

EUVD-2019-0171
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
pivotal_softwarespring_batch
𝑥
≤ 3.0.9
pivotal_softwarespring_batch
4.0.0 ≤
𝑥
≤ 4.0.1
pivotal_softwarespring_batch
4.1.0
𝑥
= Vulnerable software versions
References