CVE-2019-3774

EPSS 2.0%

Low severity vulnerability that affects org.springframework.batch:spring-batch-core

Published: 1/25/2019Modified: 9/23/2025
Also known as:GHSA-3wc8-659g-r88q

Description

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Affected packages (1)

References (21)