CVE-2013-6429
published 2014-01-26CVE-2013-6429: The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which…
PriorityP355medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
90.45%
99.8th percentile
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 3.0.6.RELEASE-13 (bookworm) | libspring-java 3.0.6.RELEASE-13 (bookworm) |
| debian | libspring-java | < libspring-java 3.0.6.RELEASE-11 (bookworm) | libspring-java 3.0.6.RELEASE-11 (bookworm) |
| pivotal_software | spring_framework | 3.0.0 – 3.2.4 | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| vmware | spring_framework | <= 3.2.7 | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerable component is SourceHttpMessageConverter in Spring MVC; look for Spring Framework versions before 3.2.5 or 4.0.0.M1 through 4.0.0.RC1 processing user-supplied XML without external entity resolution disabled. ↗
- →The upstream patch commit can be used as a reference to identify unpatched deployments or to build detection logic around the absence of the fix. ↗
- ·The patch disables external entity processing by default but provides a configuration directive to re-enable it; ensure that directive is not set to re-enable XXE in production deployments. ↗
- ·CVE-2013-6429 is considered a result of an incomplete fix for CVE-2013-4152; environments that applied the CVE-2013-4152 patch may still be vulnerable via SourceHttpMessageConverter. ↗
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa6.8MEDIUM
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
vendor_redhat·2014-01-31·CVSS 6.8
CVE-2014-0054 [MEDIUM] Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
Statement: The Red Hat Security Response Team has rated this issue as having Moderate security impact. OpenShift Enterprise 1 is currently in the Production 1 phase of its lifecycle, as such this issue is not currently planned to be addressed in future updates. For additional information, refer to the Sat
Red Hat
Framework: XML External Entity (XXE) injection flaw
vendor_redhat·2014-01-14·CVSS 6.8
CVE-2013-6429 [MEDIUM] CWE-611 Framework: XML External Entity (XXE) injection flaw
Framework: XML External Entity (XXE) injection flaw
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
Package: activemq (OpenShift Enterprise 1) - Will not fix
Package: jasperreports-server-pro (Red Hat Enterprise Virtualization 3) - Will not fix
Package: activemq (Red Hat OpenShift Enterprise 2) - Will not fix
Debian
CVE-2014-0054: libspring-java - The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework befor...
vendor_debian·2014·CVSS 6.8
CVE-2014-0054 [MEDIUM] CVE-2014-0054: libspring-java - The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework befor...
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
Scope: local
bookworm: resolved (fixed in 3.0.6.RELEASE-13)
bullseye: resolved (fixed in 3.0.6.RELEASE-13)
forky: resolved (fixed in 3.0.6.RELEASE-13)
sid: resolved (fixed in 3.0.6.RELEASE-13)
trixie: resolved (fixed in 3.0.6.RELEASE-13)
Debian
CVE-2013-6429: libspring-java - The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 an...
vendor_debian·2013·CVSS 6.8
CVE-2013-6429 [MEDIUM] CVE-2013-6429: libspring-java - The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 an...
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
Scope: local
bookworm: resolved (fixed in 3.0.6.RELEASE-11)
bullseye: resolved (fixed in 3.0.6.RELEASE-11)
forky: resolved (fixed in 3.0.6.RELEASE-11)
sid: resolved (fixed in 3.0.6.RELEASE-11)
trixie: resolved (fixed in 3.0.6.RELEASE-11)
GHSA
Cross-Site Request Forgery in Spring Framework
ghsa·2022-05-13·CVSS 6.8
CVE-2014-0054 [MEDIUM] CWE-352 Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
GHSA
Cross-Site Request Forgery in Spring Framework
ghsa·2022-05-13·CVSS 6.8
CVE-2013-6429 [MEDIUM] CWE-352 Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
OSV
Cross-Site Request Forgery in Spring Framework
osv·2022-05-13·CVSS 6.8
CVE-2013-6429 [MEDIUM] Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
OSV
Cross-Site Request Forgery in Spring Framework
osv·2022-05-13·CVSS 6.8
CVE-2014-0054 [MEDIUM] Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
OSV
CVE-2014-0054: The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3
osv·2014-04-17·CVSS 6.8
CVE-2014-0054 [MEDIUM] CVE-2014-0054: The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
OSV
CVE-2013-6429: The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3
osv·2014-01-26·CVSS 6.8
CVE-2013-6429 [MEDIUM] CVE-2013-6429: The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0054 Spring Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
bugzilla·2014-03-12·CVSS 6.8
CVE-2014-0054 [MEDIUM] CVE-2014-0054 Spring Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
CVE-2014-0054 Spring Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
The fixes for the CVE-2013-7315 (bug 1061509) and CVE-2013-6429 (bug 1053290) XML External Entity (XXE) issues were found to be incomplete. From the original advisory:
"Spring MVC's Jaxb2RootElementHttpMessageConverter also processed user provided XML and neither disabled XML external entities nor provided an option to disable them. Jaxb2RootElementHttpMessageConverter has been modified to provide an option to control the processing of XML external entities and that processing is now disabled by default."
This issue affects versions 3.0.0 to 3.2.8, and versions 4.0.0 to 4.0.1.
External References:
http://www.gopivotal.com/security/cve-2014-0054
Discussion:
Statement:
The Red Hat Security Response Team ha
Bugzilla
CVE-2013-6429 Spring Framework: XML External Entity (XXE) injection flaw
bugzilla·2014-01-14·CVSS 6.8
CVE-2013-6429 [MEDIUM] CVE-2013-6429 Spring Framework: XML External Entity (XXE) injection flaw
CVE-2013-6429 Spring Framework: XML External Entity (XXE) injection flaw
It was found that the Spring MVC SourceHttpMessageConverter processed user-provided XML, and did not expose any property for disabling entity resolution in the XML. A remote attacker could use this flaw to conduct XML External Entity (XXE) attacks on web sites, and read files in the context of the user running the application server. The patch for this flaw disables external entity processing by default, and provides a configuration directive to re-enable it. This flaw is considered to be the result of an incomplete fix for CVE-2013-4152.
Discussion:
The upstream git commit to correct this issue is here:
https://github.com/spring-projects/spring-framework/commit/2ae6a6a3415eebc57babcb9d3e5505887eda6d8a
External
http://rhn.redhat.com/errata/RHSA-2014-0400.htmlhttp://secunia.com/advisories/57915http://www.gopivotal.com/security/cve-2013-6429http://www.securityfocus.com/archive/1/530770/100/0/threadedhttp://www.securityfocus.com/bid/64947https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755https://jira.springsource.org/browse/SPR-11078?page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanelhttp://rhn.redhat.com/errata/RHSA-2014-0400.htmlhttp://secunia.com/advisories/57915http://www.gopivotal.com/security/cve-2013-6429http://www.securityfocus.com/archive/1/530770/100/0/threadedhttp://www.securityfocus.com/bid/64947https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755https://jira.springsource.org/browse/SPR-11078?page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel
2014-01-26
Published