Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.springframework.batch:spring-batch-core(Maven) | 0 | 3.0.10.RELEASE | N/A |
| org.springframework.batch:spring-batch-core(Maven) | 4.0.0.RELEASE | 4.0.2.RELEASE | N/A |
| org.springframework.batch:spring-batch-core(Maven) | 4.1.0.RELEASE | 4.1.1.RELEASE | N/A |
CVSS Metrics