原始 OSV JSON{
"id": "GHSA-6v7w-535j-rq5m",
"aliases": [
"CVE-2015-3192"
],
"details": "Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.",
"summary": "Pivotal Spring Framework DoS Attack with XML Input",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "3.2.14"
}
]
}
],
"package": {
"name": "org.springframework:spring-web",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.1.7"
}
]
}
],
"package": {
"name": "org.springframework:spring-web",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "5.0.0.RC2"
},
{
"fixed": "5.0.0.RC3"
}
]
}
],
"package": {
"name": "org.springframework:spring-web",
"ecosystem": "Maven"
},
"versions": [
"5.0.0.RC2"
]
}
],
"modified": "2024-03-05T18:17:31Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"published": "2018-10-17T20:29:12Z",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2015-3192",
"type": "ADVISORY"
},
{
"url": "https://github.com/spring-projects/spring-framework/issues/17727",
"type": "WEB"
},
{
"url": "https://github.com/spring-projects/spring-framework/issues/20352",
"type": "WEB"
},
{
"url": "https://github.com/spring-projects/spring-framework/commit/0411435bac835de88a80a64b3f67b1b89244e907",
"type": "WEB"
},
{
"url": "https://github.com/spring-projects/spring-framework/commit/38b8262e1e2db9be9d2171d81547da5c65ba7e09",
"type": "WEB"
},
{
"url": "https://github.com/spring-projects/spring-framework/commit/5a711c05ec750f069235597173084c2ee7962424",
"type": "WEB"
},
{
"url": "https://github.com/spring-projects/spring-framework/commit/9c3580d04e84d25a90ef4c249baee1b4e02df15e",
"type": "WEB"
},
{
"url": "https://github.com/spring-projects/spring-framework/commit/d79ec68db40c381b8e205af52748ebd3163ee33b",
"type": "WEB"
},
{
"url": "https://github.com/spring-projects/spring-framework/commit/e4651d6b50c5bc85c84ff537859c212ac4e33434",
"type": "WEB"
},
{
"url": "https://spring.io/security/cve-2015-3192",
"type": "WEB"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html",
"type": "WEB"
},
{
"url": "https://jira.spring.io/browse/SPR-13136?redirect=false",
"type": "WEB"
},
{
"url": "https://jira.spring.io/browse/SPR-13136",
"type": "WEB"
},
{
"url": "https://github.com/spring-projects/spring-framework",
"type": "PACKAGE"
},
{
"url": "https://github.com/advisories/GHSA-6v7w-535j-rq5m",
"type": "ADVISORY"
},
{
"url": "https://access.redhat.com/errata/RHSA-2016:1219",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2016:1218",
"type": "WEB"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162015.html",
"type": "WEB"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162017.html",
"type": "WEB"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2016-1592.html",
"type": "WEB"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2016-1593.html",
"type": "WEB"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2016-2035.html",
"type": "WEB"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2016-2036.html",
"type": "WEB"
},
{
"url": "http://www.securityfocus.com/bid/90853",
"type": "WEB"
},
{
"url": "http://www.securitytracker.com/id/1036587",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": "2016-07-12T19:59:00Z",
"github_reviewed_at": "2020-06-16T21:20:17Z"
}
}