cbcvebase.
CVE-2013-4152
published 2014-01-23

CVE-2013-4152: The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows…

PriorityP348medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
26.47%
97.8th percentile
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibspring-java< libspring-java 3.0.6.RELEASE-13 (bookworm)libspring-java 3.0.6.RELEASE-13 (bookworm)
debianlibspring-java< libspring-java 3.0.6.RELEASE-11 (bookworm)libspring-java 3.0.6.RELEASE-11 (bookworm)
debianlibspring-java< libspring-java 3.0.6.RELEASE-10 (bookworm)libspring-java 3.0.6.RELEASE-10 (bookworm)
pivotal_softwarespring_framework3.0.0 – 3.2.4
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
vmwarespring_framework<= 3.2.3
vmwarespring_framework<= 3.2.7
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework

Detection & IOCsextracted from sources · hover to see the quote

  • Detect XXE exploitation attempts targeting Spring OXM/JAXB marshaller via crafted XML with external entity declarations in DOMSource, StAXSource, SAXSource, or StreamSource inputs
  • Monitor for inbound XML payloads containing external entity declarations (DOCTYPE with SYSTEM or PUBLIC identifiers) directed at Spring Framework endpoints using JAXB marshalling
  • ·CVE-2013-4152 affects Spring Framework before 3.2.4 and 4.0.0.M1 only; later related CVEs (CVE-2013-7315, CVE-2013-6429, CVE-2014-0054) cover different affected version ranges and components, indicating successive incomplete fixes — ensure all related CVEs are patched together
  • ·The Spring OXM wrapper's JAXB marshaller is the specific vulnerable component for CVE-2013-4152; verify that entity resolution is explicitly disabled in all XML input factory configurations (DOMSource, StAXSource, SAXSource, StreamSource)
  • ·CVE-2013-7315 is a distinct split from CVE-2013-4152 covering the StAX XMLInputFactory in Spring MVC; patching CVE-2013-4152 alone does not remediate the StAX vector

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa6.8MEDIUM
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.