← Back

Xmlbeam

xmlbeam

Vendor: Xmlbeam • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Broadcom
Pivotal SoftwareVmware+1 more
5Spring Data Commons
Spring Data CommonsSpring Data Rest+2 more
Jun 26, 2026
May 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML exte...Show more
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.Show less