[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2890-1 libspring-java -- libspring-java

ID: oval:org.secpod.oval:def:601250Date: (C)2014-07-23   (M)2022-10-10
Class: PATCHFamily: unix




Two vulnerabilities were discovered in libspring-java, the Debian package for the Java Spring framework. CVE-2014-0054 Jaxb2RootElementHttpMessageConverter in Spring MVC processes external XML entities. CVE-2014-1904 Spring MVC introduces a cross-site scripting vulnerability if the action on a Spring form is not specified.

Platform:
Debian 7.0
Product:
libspring-java
Reference:
DSA-2890-1
CVE-2014-0054
CVE-2014-1904
CVE    2
CVE-2014-0054
CVE-2014-1904
CPE    2
cpe:/o:debian:debian_linux:7.x
cpe:/a:springsource:libspring-java

© SecPod Technologies