Vulnerabilities > Pivotal Software > Spring Batch > 2.0.5

DATE CVE VULNERABILITY TITLE RISK
2019-01-18 CVE-2019-3774 XXE vulnerability in Pivotal Software Spring Batch
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
network
low complexity
pivotal-software CWE-611
critical
9.8