关于VU#475445漏洞是否影响Spring Security SAML2的技术问询
Does CERT Vulnerability 475445 Impact Spring Security SAML2?
Hey there, let's break this down plainly for you:
Short Answer
Nope, this vulnerability doesn't affect Spring Security SAML2 at all.
The Details
- Default security hardening: Spring Security SAML2 comes with strict XML processing protections out of the box. It explicitly disables external entity (XXE) parsing — which is exactly the vector this 475445 vulnerability targets. This means even if underlying parsing libraries had theoretical risks, Spring's configuration blocks any possible exploit path.
- No reliance on vulnerable parsers: As you observed, the affected API list for 475445 doesn't include the XML parsers Spring Security SAML2 actually uses. The framework leans on either JDK-native XML classes or Spring's own OXM utilities, neither of which are flagged in the disclosure. Even when it depends on common libraries, Spring Security's overrides ensure unsafe default behaviors are never enabled.
- No exploit conditions met: For the 475445 vulnerability to work, a parser needs to allow external entity resolution and process untrusted XML input without safeguards. Spring Security SAML2 eliminates both of these conditions by default, so there's no way for the vulnerability to be triggered here.
内容的提问来源于stack exchange,提问作者Petras Butkevicius
相关产品推荐
相关产品推荐

