CVE-2019-3774
Low severity vulnerability that affects org.springframework.batch:spring-batch-core
Description
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Base CVSS
9.8
EPSS Score
2.11%
Introduced Version
1.0.0.FINAL
Fix Available
3.0.10.RELEASE,4.0.2.RELEASE,4.1.1.RELEASE