CVE-2019-3773
Executive Summary
CVE-2019-3773 exposes Spring Web Services (v2.4.3, v3.0.4, and older unsupported releases) to XML External Entity (XXE) injection when processing XML from untrusted sources. Attackers can read arbitrary files, cause DoS, or execute remote code via crafted XML. No CISA KEV listing yet; mitigations include disabling external entities, updating to patched versions, and validating XML input.
Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2019-01-18T22:29:01.020 - Last Modified: 2026-09-04T13:45:35.430
Original Description: Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
"Nothing strengthens authority so much as silence."
— Leonardo da Vinci