Back to Database
Status published
Critical
CVE-2019-3772
Spring Integration XML External Entity Injection (XXE)
Vulnerability Description
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-3772
Credits & Attribution
No credits recorded in the NVD database.
References
More from Spring
View All →CVE-2025-41243
Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
Critical
10
CVE-2025-41232
CVE-2025-41232: Spring Security authorization bypass for method security annotations on private methods
Critical
9.1
CVE-2025-22235
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
High
7.3
CVE-2025-22234
Spring Security - BCrypt Password Encoder maximum password length breaks timing attack mitigation
Medium
5.3
CVE-2025-22233
Spring Framework DataBinder Case Sensitive Match Exception
Low
3.1
Affected Vendor
Spring
View all reports →Affected Software
Spring Integration
Vulnerable Versions:
5.0, 5.1, 4.3
Timeline
Official Publish:
January 18th, 2019
Last Modified:
September 16th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H