Welcome to OGeek Q&A Community for programmer and developer-Open, Learning and Share
Welcome To Ask or Share your Answers For Others

Categories

0 votes
620 views
in Technique[技术] by (71.8m points)

spring-boot 2.3.7 spring-boot-starter-integration CVE-2019-3772

I am getting from the tool Dependency-Checker on Sonar following:

Filename: spring-boot-starter-integration-2.3.7.RELEASE.jar | Reference: CVE-2019-3772 | CVSS Score: 9.8 | Category: CWE-611 | Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

I am using spring boot 2.3.7.RELEASE. The Version of Spring-Frameworks are Spring 5.2.12.RELEASE and Spring-Integration 5.3.4.RELEASE. There are no older Spring Dependencies in the dependency tree. Few application modules are using Spring-AOP (not sure the combination spring-integration and spring-aop cause that issue???).

Are there any known CVE issues in combination with Spring-Integration and Spring-AOP?

I don`t know why this pops up and what could I do that it disappears.

Hints are highly welcome, thank you very much


与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
Welcome To Ask or Share your Answers For Others

1 Reply

0 votes
by (71.8m points)
等待大神答复

与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
OGeek|极客中国-欢迎来到极客的世界,一个免费开放的程序员编程交流平台!开放,进步,分享!让技术改变生活,让极客改变未来! Welcome to OGeek Q&A Community for programmer and developer-Open, Learning and Share
Click Here to Ask a Question

...