CVE-2019-3774

CRITICAL

Spring Batch < 3.0.9 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

References (20)

Core 20
Core References
Mitigation, Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2019-3774

Scores

CVSS v3 9.8
EPSS 0.0303
EPSS Percentile 85.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (3)
org.springframework.batch/spring-batch-core 0 - 3.0.10.RELEASEMaven
pivotal_software/spring_batch 4.1.0
pivotal_software/spring_batch < 3.0.9
Published Jan 18, 2019
Tracked Since Feb 18, 2026