CVE-2013-6430

Severity
5.4MEDIUM
EPSS
0.3%
top 45.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateMay 5

Description

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or (3) left or (4) right angle bracket.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages4 packages

Mavenorg.springframework:spring-web< 3.2.2.RELEASE
Debianlibspring-java< 3.0.6.RELEASE-11+3
CVEListV5pivotal/spring_mvcbefore 3.2.2

Patches

🔴Vulnerability Details

4
OSV
Improper Neutralization of Input During Web Page Generation in Spring Framework2022-05-05
GHSA
Improper Neutralization of Input During Web Page Generation in Spring Framework2022-05-05
OSV
CVE-2013-6430: The JavaScriptUtils2020-01-10
CVEList
CVE-2013-6430: The JavaScriptUtils2020-01-10

📋Vendor Advisories

2
Red Hat
Framework: org.spring.web.util.JavaScriptUtils.javaScriptEscape insufficient escaping of characters2014-01-14
Debian
CVE-2013-6430: libspring-java - The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in ...2013

💬Community

1
Bugzilla
CVE-2013-6430 Spring Framework: org.spring.web.util.JavaScriptUtils.javaScriptEscape insufficient escaping of characters2013-12-10