GHSA-f93f-g33r-8pcp · Severity: high · Ecosystem: maven — Improper Restriction of XML External Entity Reference in Spring Framework
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
Conclusion & alert: CVE-2014-0225 is rated Moderate Risk (51.3/100): CVSS High severity, with low exploitation likelihood (EPSS 0.23%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-07-23 | 0.25% | 0.23% | -0.02% |
| 2 | 2025-04-20 | 0.38% | 0.25% | -0.13% |
| 3 | 2025-04-18 | — | 0.38% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.0 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
GHSA-f93f-g33r-8pcp · Severity: high · Ecosystem: maven — Improper Restriction of XML External Entity Reference in Spring Framework
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
low | CVE-2014-0225 low priority: Debian including 1 source packages (libspring-java), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2014-0225 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2014-0225 |
ubuntu
|
medium | CVE-2014-0225 medium priority: Ubuntu including 1 source packages (libspring-java), 21 status rows across 21 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, lucid, precise, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): not-affected 10, ignored 8, DNE 1, needs-triage 1, released 1. | https://ubuntu.com/security/CVE-2014-0225 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| pivotal_software | spring_framework | 3.0.0 | cpe:2.3:a:pivotal_software:spring_framework:3.0.0:*:*:*:*:*:*:* |
| pivotal_software | spring_framework | 3.1.0 | cpe:2.3:a:pivotal_software:spring_framework:3.1.0:*:*:*:*:*:*:* |
| pivotal_software | spring_framework | 3.2.0 | cpe:2.3:a:pivotal_software:spring_framework:3.2.0:*:*:*:*:*:*:* |
| pivotal_software | spring_framework | 4.0.0 | cpe:2.3:a:pivotal_software:spring_framework:4.0.0:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.0.1 | cpe:2.3:a:vmware:spring_framework:3.0.1:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.0.2 | cpe:2.3:a:vmware:spring_framework:3.0.2:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.0.3 | cpe:2.3:a:vmware:spring_framework:3.0.3:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.0.4 | cpe:2.3:a:vmware:spring_framework:3.0.4:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.0.5 | cpe:2.3:a:vmware:spring_framework:3.0.5:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.0.6 | cpe:2.3:a:vmware:spring_framework:3.0.6:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.0.7 | cpe:2.3:a:vmware:spring_framework:3.0.7:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.1.0 | cpe:2.3:a:vmware:spring_framework:3.1.0:rc1:*:*:*:*:*:* |
| vmware | spring_framework | 3.1.0 | cpe:2.3:a:vmware:spring_framework:3.1.0:rc2:*:*:*:*:*:* |
| vmware | spring_framework | 3.1.1 | cpe:2.3:a:vmware:spring_framework:3.1.1:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.1.2 | cpe:2.3:a:vmware:spring_framework:3.1.2:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.1.3 | cpe:2.3:a:vmware:spring_framework:3.1.3:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.1.4 | cpe:2.3:a:vmware:spring_framework:3.1.4:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.0 | cpe:2.3:a:vmware:spring_framework:3.2.0:rc1:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.0 | cpe:2.3:a:vmware:spring_framework:3.2.0:rc2:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.0 | cpe:2.3:a:vmware:spring_framework:3.2.0:rc2-a:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.1 | cpe:2.3:a:vmware:spring_framework:3.2.1:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.2 | cpe:2.3:a:vmware:spring_framework:3.2.2:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.3 | cpe:2.3:a:vmware:spring_framework:3.2.3:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.4 | cpe:2.3:a:vmware:spring_framework:3.2.4:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.5 | cpe:2.3:a:vmware:spring_framework:3.2.5:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.6 | cpe:2.3:a:vmware:spring_framework:3.2.6:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.7 | cpe:2.3:a:vmware:spring_framework:3.2.7:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.8 | cpe:2.3:a:vmware:spring_framework:3.2.8:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.0 | cpe:2.3:a:vmware:spring_framework:4.0.0:rc1:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.0 | cpe:2.3:a:vmware:spring_framework:4.0.0:rc2:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.1 | cpe:2.3:a:vmware:spring_framework:4.0.1:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.2 | cpe:2.3:a:vmware:spring_framework:4.0.2:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.3 | cpe:2.3:a:vmware:spring_framework:4.0.3:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.4 | cpe:2.3:a:vmware:spring_framework:4.0.4:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://pivotal.io/security/cve-2014-0225 | Vendor Advisory |