Pivotal Spring Framework DoS Attack with XML Input
Moderate severity
GitHub Reviewed
Published
Oct 17, 2018
to the GitHub Advisory Database
•
Updated Mar 15, 2024
Package
Affected versions
< 3.2.14
>= 4.0.0, < 4.1.7
= 5.0.0.RC2
Patched versions
3.2.14
4.1.7
5.0.0.RC3
Description
Published by the National Vulnerability Database
Jul 12, 2016
Published to the GitHub Advisory Database
Oct 17, 2018
Reviewed
Jun 16, 2020
Last updated
Mar 15, 2024
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
References