CVE-2013-4152
published 2014-01-23CVE-2013-4152: The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows…
PriorityP348medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
26.47%
97.8th percentile
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 3.0.6.RELEASE-13 (bookworm) | libspring-java 3.0.6.RELEASE-13 (bookworm) |
| debian | libspring-java | < libspring-java 3.0.6.RELEASE-11 (bookworm) | libspring-java 3.0.6.RELEASE-11 (bookworm) |
| debian | libspring-java | < libspring-java 3.0.6.RELEASE-10 (bookworm) | libspring-java 3.0.6.RELEASE-10 (bookworm) |
| pivotal_software | spring_framework | 3.0.0 – 3.2.4 | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| vmware | spring_framework | <= 3.2.3 | — |
| vmware | spring_framework | <= 3.2.7 | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect XXE exploitation attempts targeting Spring OXM/JAXB marshaller via crafted XML with external entity declarations in DOMSource, StAXSource, SAXSource, or StreamSource inputs ↗
- →Monitor for inbound XML payloads containing external entity declarations (DOCTYPE with SYSTEM or PUBLIC identifiers) directed at Spring Framework endpoints using JAXB marshalling ↗
- ·CVE-2013-4152 affects Spring Framework before 3.2.4 and 4.0.0.M1 only; later related CVEs (CVE-2013-7315, CVE-2013-6429, CVE-2014-0054) cover different affected version ranges and components, indicating successive incomplete fixes — ensure all related CVEs are patched together ↗
- ·The Spring OXM wrapper's JAXB marshaller is the specific vulnerable component for CVE-2013-4152; verify that entity resolution is explicitly disabled in all XML input factory configurations (DOMSource, StAXSource, SAXSource, StreamSource) ↗
- ·CVE-2013-7315 is a distinct split from CVE-2013-4152 covering the StAX XMLInputFactory in Spring MVC; patching CVE-2013-4152 alone does not remediate the StAX vector ↗
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa6.8MEDIUM
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
vendor_redhat·2014-01-31·CVSS 6.8
CVE-2014-0054 [MEDIUM] Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
Statement: The Red Hat Security Response Team has rated this issue as having Moderate security impact. OpenShift Enterprise 1 is currently in the Production 1 phase of its lifecycle, as such this issue is not currently planned to be addressed in future updates. For additional information, refer to the Sat
Red Hat
Framework: XML External Entity (XXE) injection flaw
vendor_redhat·2014-01-14·CVSS 6.8
CVE-2013-6429 [MEDIUM] CWE-611 Framework: XML External Entity (XXE) injection flaw
Framework: XML External Entity (XXE) injection flaw
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
Package: activemq (OpenShift Enterprise 1) - Will not fix
Package: jasperreports-server-pro (Red Hat Enterprise Virtualization 3) - Will not fix
Package: activemq (Red Hat OpenShift Enterprise 2) - Will not fix
Debian
CVE-2014-0054: libspring-java - The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework befor...
vendor_debian·2014·CVSS 6.8
CVE-2014-0054 [MEDIUM] CVE-2014-0054: libspring-java - The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework befor...
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
Scope: local
bookworm: resolved (fixed in 3.0.6.RELEASE-13)
bullseye: resolved (fixed in 3.0.6.RELEASE-13)
forky: resolved (fixed in 3.0.6.RELEASE-13)
sid: resolved (fixed in 3.0.6.RELEASE-13)
trixie: resolved (fixed in 3.0.6.RELEASE-13)
Red Hat
Framework: XML External Entity (XXE) injection flaw
vendor_redhat·2013-08-22·CVSS 6.8
CVE-2013-4152 [MEDIUM] Framework: XML External Entity (XXE) injection flaw
Framework: XML External Entity (XXE) injection flaw
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
Debian
CVE-2013-6429: libspring-java - The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 an...
vendor_debian·2013·CVSS 6.8
CVE-2013-6429 [MEDIUM] CVE-2013-6429: libspring-java - The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 an...
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
Scope: local
bookworm: resolved (fixed in 3.0.6.RELEASE-11)
bullseye: resolved (fixed in 3.0.6.RELEASE-11)
forky: resolved (fixed in 3.0.6.RELEASE-11)
sid: resolved (fixed in 3.0.6.RELEASE-11)
trixie: resolved (fixed in 3.0.6.RELEASE-11)
Debian
CVE-2013-4152: libspring-java - The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using...
vendor_debian·2013·CVSS 6.8
CVE-2013-4152 [MEDIUM] CVE-2013-4152: libspring-java - The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using...
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
Scope: local
bookworm: resolved (fixed in 3.0.6.RELEASE-10)
bullseye: resolved (fixed in 3.0.6.RELEASE-10)
forky: resolved (fixed in 3.0.6.RELEASE-10)
sid: resolved (fixed in 3.0.6.RELEASE-10)
trixie: resolved (fixed in 3.0.6.RELEASE-10)
Debian
CVE-2013-7315: libspring-java - The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 do...
vendor_debian·2013·CVSS 6.8
CVE-2013-7315 [MEDIUM] CVE-2013-7315: libspring-java - The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 do...
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.
Scope: local
bookworm: resolved (fixed in 3.0.6.RELEASE-10)
bullseye: resolved (fixed in 3.0.6.RELEASE-10)
forky: resolved (fixed in 3.0.6.RELEASE-10)
sid: resolved (fixed in 3.0.6.RELEASE-10)
trixie: resolved (fixed in 3.0.6.RELEASE-10)
GHSA
GHSA-cv36-jhxc-fvcj: In WS-Inc J WBEM Server 4
ghsa_unreviewed·2023-08-03·CVSS 6.8
CVE-2023-37364 [MEDIUM] CWE-611 GHSA-cv36-jhxc-fvcj: In WS-Inc J WBEM Server 4
In WS-Inc J WBEM Server 4.7.4 before 4.7.5, the CIM-XML protocol adapter does not disable entity resolution. This allows context-dependent attackers to read arbitrary files or cause a denial of service, a similar issue to CVE-2013-4152.
GHSA
Cross-Site Request Forgery in Spring Framework
ghsa·2022-05-13·CVSS 6.8
CVE-2014-0054 [MEDIUM] CWE-352 Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
OSV
Missing XML Validation in Spring Framework
osv·2022-05-13·CVSS 6.8
CVE-2013-7315 [MEDIUM] Missing XML Validation in Spring Framework
Missing XML Validation in Spring Framework
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.
GHSA
Cross-Site Request Forgery in Spring Framework
ghsa·2022-05-13·CVSS 6.8
CVE-2013-6429 [MEDIUM] CWE-352 Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
OSV
Cross-Site Request Forgery in Spring Framework
osv·2022-05-13
CVE-2013-4152 [MEDIUM] Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
OSV
Cross-Site Request Forgery in Spring Framework
osv·2022-05-13·CVSS 6.8
CVE-2013-6429 [MEDIUM] Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
GHSA
Cross-Site Request Forgery in Spring Framework
ghsa·2022-05-13
CVE-2013-4152 [MEDIUM] CWE-352 Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
GHSA
Missing XML Validation in Spring Framework
ghsa·2022-05-13·CVSS 6.8
CVE-2013-7315 [MEDIUM] CWE-112 Missing XML Validation in Spring Framework
Missing XML Validation in Spring Framework
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.
OSV
Cross-Site Request Forgery in Spring Framework
osv·2022-05-13·CVSS 6.8
CVE-2014-0054 [MEDIUM] Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
OSV
CVE-2014-0054: The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3
osv·2014-04-17·CVSS 6.8
CVE-2014-0054 [MEDIUM] CVE-2014-0054: The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
OSV
CVE-2013-6429: The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3
osv·2014-01-26·CVSS 6.8
CVE-2013-6429 [MEDIUM] CVE-2013-6429: The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
OSV
CVE-2013-7315: The Spring MVC in Spring Framework before 3
osv·2014-01-23·CVSS 6.8
CVE-2013-7315 [MEDIUM] CVE-2013-7315: The Spring MVC in Spring Framework before 3
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.
OSV
CVE-2013-4152: The Spring OXM wrapper in Spring Framework before 3
osv·2014-01-23·CVSS 6.8
CVE-2013-4152 [MEDIUM] CVE-2013-4152: The Spring OXM wrapper in Spring Framework before 3
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6429 Spring Framework: XML External Entity (XXE) injection flaw
bugzilla·2014-01-14·CVSS 6.8
CVE-2013-6429 [MEDIUM] CVE-2013-6429 Spring Framework: XML External Entity (XXE) injection flaw
CVE-2013-6429 Spring Framework: XML External Entity (XXE) injection flaw
It was found that the Spring MVC SourceHttpMessageConverter processed user-provided XML, and did not expose any property for disabling entity resolution in the XML. A remote attacker could use this flaw to conduct XML External Entity (XXE) attacks on web sites, and read files in the context of the user running the application server. The patch for this flaw disables external entity processing by default, and provides a configuration directive to re-enable it. This flaw is considered to be the result of an incomplete fix for CVE-2013-4152.
Discussion:
The upstream git commit to correct this issue is here:
https://github.com/spring-projects/spring-framework/commit/2ae6a6a3415eebc57babcb9d3e5505887eda6d8a
External
Bugzilla
CVE-2013-4152 Spring Framework: XML External Entity (XXE) injection flaw
bugzilla·2013-08-22·CVSS 6.8
CVE-2013-4152 [MEDIUM] CVE-2013-4152 Spring Framework: XML External Entity (XXE) injection flaw
CVE-2013-4152 Spring Framework: XML External Entity (XXE) injection flaw
It was reported [1] that the Spring Framework suffered from several XML External Entity (XXE) flaws:
Versions Affected:
- 3.0.0 to 3.2.3 (Spring OXM)
- 3.2.0 to 3.2.3 (Spring MVC)
- 4.0.0.M1 (Spring OXM)
- 4.0.0.M1-4.0.0.M2 (Spring MVC)
- Earlier unsupported versions may also be affected
Description:
The Spring OXM wrapper did not expose any property for disabling entity resolution when using the JAXB unmarshaller.
There are four possible source implementations passed to the unmarshaller:
- DOMSource
- StAXSource
- SAXSource
- StreamSource
For a DOMSource, the XML has already been parsed by user code and that code is responsible for protecting against XXE.
For a StAXSource, the XMLStreamReader has already been crea
http://rhn.redhat.com/errata/RHSA-2014-0212.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0254.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0400.htmlhttp://seclists.org/bugtraq/2013/Aug/154http://seclists.org/fulldisclosure/2013/Nov/14http://secunia.com/advisories/56247http://secunia.com/advisories/57915http://www.debian.org/security/2014/dsa-2842http://www.gopivotal.com/security/cve-2013-4152http://www.securityfocus.com/bid/61951https://github.com/spring-projects/spring-framework/pull/317/fileshttps://jira.springsource.org/browse/SPR-10806http://rhn.redhat.com/errata/RHSA-2014-0212.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0254.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0400.htmlhttp://seclists.org/bugtraq/2013/Aug/154http://seclists.org/fulldisclosure/2013/Nov/14http://secunia.com/advisories/56247http://secunia.com/advisories/57915http://www.debian.org/security/2014/dsa-2842http://www.gopivotal.com/security/cve-2013-4152http://www.securityfocus.com/bid/61951https://github.com/spring-projects/spring-framework/pull/317/fileshttps://jira.springsource.org/browse/SPR-10806
2014-01-23
Published