2019-01-18 17:05:53 -05:00
{
2019-04-23 20:01:18 +00:00
"CVE_data_meta" : {
"ASSIGNER" : "security_alert@emc.com" ,
"DATE_PUBLIC" : "2019-01-15T20:30:16.000Z" ,
"ID" : "CVE-2019-3772" ,
"STATE" : "PUBLIC" ,
"TITLE" : "Spring Integration XML External Entity Injection (XXE) "
2019-03-17 23:20:33 +00:00
} ,
2019-04-23 20:01:18 +00:00
"affects" : {
"vendor" : {
"vendor_data" : [
2019-03-17 23:20:33 +00:00
{
2019-04-23 20:01:18 +00:00
"product" : {
"product_data" : [
2019-03-17 23:20:33 +00:00
{
2019-04-23 20:01:18 +00:00
"product_name" : "Spring Integration" ,
"version" : {
"version_data" : [
2019-03-17 23:20:33 +00:00
{
2019-04-23 20:01:18 +00:00
"affected" : "<" ,
"version_name" : "5.0" ,
"version_value" : "v5.0.10.RELEASE"
2019-03-17 23:20:33 +00:00
} ,
{
2019-04-23 20:01:18 +00:00
"affected" : "<" ,
"version_name" : "5.1" ,
"version_value" : "v5.1.1.RELEASE"
2019-03-17 23:20:33 +00:00
} ,
{
2019-04-23 20:01:18 +00:00
"affected" : "<" ,
"version_name" : "4.3" ,
"version_value" : "v4.3.18.RELEASE"
2019-03-17 23:20:33 +00:00
}
]
}
}
]
} ,
2019-04-23 20:01:18 +00:00
"vendor_name" : "Spring"
2019-03-17 23:20:33 +00:00
}
]
}
} ,
2019-04-23 20:01:18 +00:00
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
2019-01-18 17:05:53 -05:00
{
2019-04-23 20:01:18 +00:00
"lang" : "eng" ,
"value" : "Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources."
2019-01-18 17:05:53 -05:00
}
2019-03-17 23:20:33 +00:00
]
} ,
2019-04-23 20:01:18 +00:00
"impact" : null ,
"problemtype" : {
"problemtype_data" : [
2019-03-17 23:20:33 +00:00
{
2019-04-23 20:01:18 +00:00
"description" : [
2019-03-17 23:20:33 +00:00
{
2019-04-23 20:01:18 +00:00
"lang" : "eng" ,
"value" : "CWE-611: XML External Entities (XXE)"
2019-03-17 23:20:33 +00:00
}
]
}
]
} ,
2019-04-23 20:01:18 +00:00
"references" : {
"reference_data" : [
2019-03-17 23:20:33 +00:00
{
2019-04-23 20:01:18 +00:00
"name" : "https://pivotal.io/security/cve-2019-3772" ,
"refsource" : "CONFIRM" ,
"url" : "https://pivotal.io/security/cve-2019-3772"
2019-04-17 10:00:41 +00:00
} ,
{
2019-04-23 20:01:18 +00:00
"url" : "https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"
2019-04-23 04:53:58 -07:00
} ,
{
2019-04-23 20:01:18 +00:00
"refsource" : "BID" ,
"name" : "106749" ,
"url" : "http://www.securityfocus.com/bid/106749"
2019-03-17 23:20:33 +00:00
}
]
} ,
2019-04-23 20:01:18 +00:00
"source" : {
"discovery" : "UNKNOWN"
2019-03-17 23:20:33 +00:00
}
}