I am getting from the tool Dependency-Checker on Sonar following:
Filename: spring-boot-starter-integration-2.3.7.RELEASE.jar | Reference: CVE-2019-3772 | CVSS Score: 9.8 | Category: CWE-611 | Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
I am using spring boot 2.3.7.RELEASE
. The Version of Spring-Frameworks are Spring 5.2.12.RELEASE
and Spring-Integration 5.3.4.RELEASE
. There are no older Spring Dependencies in the dependency tree. Few application modules are using Spring-AOP (not sure the combination spring-integration and spring-aop cause that issue???).
Are there any known CVE issues in combination with Spring-Integration and Spring-AOP?
I don`t know why this pops up and what could I do that it disappears.
Hints are highly welcome, thank you very much
与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…