cbcvebase.
CVE-2013-6429
published 2014-01-26

CVE-2013-6429: The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which…

PriorityP355medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
90.45%
99.8th percentile
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibspring-java< libspring-java 3.0.6.RELEASE-13 (bookworm)libspring-java 3.0.6.RELEASE-13 (bookworm)
debianlibspring-java< libspring-java 3.0.6.RELEASE-11 (bookworm)libspring-java 3.0.6.RELEASE-11 (bookworm)
pivotal_softwarespring_framework3.0.0 – 3.2.4
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
springsourcespring_framework
vmwarespring_framework<= 3.2.7
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework
vmwarespring_framework

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerable component is SourceHttpMessageConverter in Spring MVC; look for Spring Framework versions before 3.2.5 or 4.0.0.M1 through 4.0.0.RC1 processing user-supplied XML without external entity resolution disabled.
  • The upstream patch commit can be used as a reference to identify unpatched deployments or to build detection logic around the absence of the fix.
  • ·The patch disables external entity processing by default but provides a configuration directive to re-enable it; ensure that directive is not set to re-enable XXE in production deployments.
  • ·CVE-2013-6429 is considered a result of an incomplete fix for CVE-2013-4152; environments that applied the CVE-2013-4152 patch may still be vulnerable via SourceHttpMessageConverter.

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa6.8MEDIUM
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.