Overview
About vulnerability
When usingspring-restdocs-webtestclient or spring-restdocs-restassured to document
a remote API accessed over HTTP, an attacker who compromises the API or tricks the user
into documenting a malicious API can perform an XXE injection attack when the
documentation-generating tests are next executed.
Details
- Affected product:
- Spring
- Affected packages:
- Spring Boot @ 2.1.8.RELEASE (+80 more)