CVE-2014-0225

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
References
Link Resource
https://pivotal.io/security/cve-2014-0225 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pivotal_software:spring_framework:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.0:rc2-a:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.8:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.4:*:*:*:*:*:*:*

History

11 Apr 2022, 17:16

Type Values Removed Values Added
CPE cpe:2.3:a:pivotal_software:spring_framework:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.8:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.0.7:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.0:rc2-a:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.1.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.8:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.0:rc2-a:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.4:*:*:*:*:*:*:*

Information

Published : 2017-05-25 17:29

Updated : 2024-02-04 19:29


NVD link : CVE-2014-0225

Mitre link : CVE-2014-0225

CVE.ORG link : CVE-2014-0225


JSON object : View

Products Affected

pivotal_software

  • spring_framework

vmware

  • spring_framework
CWE
CWE-611

Improper Restriction of XML External Entity Reference