CVE-2013-7315
published 2014-01-23CVE-2013-7315: The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.44%
87.7th percentile
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 3.0.6.RELEASE-13 (bookworm) | libspring-java 3.0.6.RELEASE-13 (bookworm) |
| debian | libspring-java | < libspring-java 3.0.6.RELEASE-11 (bookworm) | libspring-java 3.0.6.RELEASE-11 (bookworm) |
| debian | libspring-java | < libspring-java 3.0.6.RELEASE-10 (bookworm) | libspring-java 3.0.6.RELEASE-10 (bookworm) |
| pivotal_software | spring_framework | 3.0.0 – 3.2.4 | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| springsource | spring_framework | — | — |
| vmware | spring_framework | <= 3.2.3 | — |
| vmware | spring_framework | <= 3.2.7 | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa6.8MEDIUM
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
vendor_redhat·2014-01-31·CVSS 6.8
CVE-2014-0054 [MEDIUM] Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
Statement: The Red Hat Security Response Team has rated this issue as having Moderate security impact. OpenShift Enterprise 1 is currently in the Production 1 phase of its lifecycle, as such this issue is not currently planned to be addressed in future updates. For additional information, refer to the Sat
Red Hat
Framework: XML External Entity (XXE) injection flaw
vendor_redhat·2014-01-14·CVSS 6.8
CVE-2013-6429 [MEDIUM] CWE-611 Framework: XML External Entity (XXE) injection flaw
Framework: XML External Entity (XXE) injection flaw
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
Package: activemq (OpenShift Enterprise 1) - Will not fix
Package: jasperreports-server-pro (Red Hat Enterprise Virtualization 3) - Will not fix
Package: activemq (Red Hat OpenShift Enterprise 2) - Will not fix
Debian
CVE-2014-0054: libspring-java - The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework befor...
vendor_debian·2014·CVSS 6.8
CVE-2014-0054 [MEDIUM] CVE-2014-0054: libspring-java - The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework befor...
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
Scope: local
bookworm: resolved (fixed in 3.0.6.RELEASE-13)
bullseye: resolved (fixed in 3.0.6.RELEASE-13)
forky: resolved (fixed in 3.0.6.RELEASE-13)
sid: resolved (fixed in 3.0.6.RELEASE-13)
trixie: resolved (fixed in 3.0.6.RELEASE-13)
Debian
CVE-2013-6429: libspring-java - The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 an...
vendor_debian·2013·CVSS 6.8
CVE-2013-6429 [MEDIUM] CVE-2013-6429: libspring-java - The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 an...
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
Scope: local
bookworm: resolved (fixed in 3.0.6.RELEASE-11)
bullseye: resolved (fixed in 3.0.6.RELEASE-11)
forky: resolved (fixed in 3.0.6.RELEASE-11)
sid: resolved (fixed in 3.0.6.RELEASE-11)
trixie: resolved (fixed in 3.0.6.RELEASE-11)
Debian
CVE-2013-7315: libspring-java - The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 do...
vendor_debian·2013·CVSS 6.8
CVE-2013-7315 [MEDIUM] CVE-2013-7315: libspring-java - The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 do...
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.
Scope: local
bookworm: resolved (fixed in 3.0.6.RELEASE-10)
bullseye: resolved (fixed in 3.0.6.RELEASE-10)
forky: resolved (fixed in 3.0.6.RELEASE-10)
sid: resolved (fixed in 3.0.6.RELEASE-10)
trixie: resolved (fixed in 3.0.6.RELEASE-10)
GHSA
Cross-Site Request Forgery in Spring Framework
ghsa·2022-05-13·CVSS 6.8
CVE-2014-0054 [MEDIUM] CWE-352 Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
OSV
Missing XML Validation in Spring Framework
osv·2022-05-13·CVSS 6.8
CVE-2013-7315 [MEDIUM] Missing XML Validation in Spring Framework
Missing XML Validation in Spring Framework
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.
GHSA
Cross-Site Request Forgery in Spring Framework
ghsa·2022-05-13·CVSS 6.8
CVE-2013-6429 [MEDIUM] CWE-352 Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
OSV
Cross-Site Request Forgery in Spring Framework
osv·2022-05-13·CVSS 6.8
CVE-2013-6429 [MEDIUM] Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
GHSA
Missing XML Validation in Spring Framework
ghsa·2022-05-13·CVSS 6.8
CVE-2013-7315 [MEDIUM] CWE-112 Missing XML Validation in Spring Framework
Missing XML Validation in Spring Framework
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.
OSV
Cross-Site Request Forgery in Spring Framework
osv·2022-05-13·CVSS 6.8
CVE-2014-0054 [MEDIUM] Cross-Site Request Forgery in Spring Framework
Cross-Site Request Forgery in Spring Framework
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
OSV
CVE-2014-0054: The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3
osv·2014-04-17·CVSS 6.8
CVE-2014-0054 [MEDIUM] CVE-2014-0054: The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
OSV
CVE-2013-6429: The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3
osv·2014-01-26·CVSS 6.8
CVE-2013-6429 [MEDIUM] CVE-2013-6429: The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
OSV
CVE-2013-7315: The Spring MVC in Spring Framework before 3
osv·2014-01-23·CVSS 6.8
CVE-2013-7315 [MEDIUM] CVE-2013-7315: The Spring MVC in Spring Framework before 3
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0054 Spring Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
bugzilla·2014-03-12·CVSS 6.8
CVE-2014-0054 [MEDIUM] CVE-2014-0054 Spring Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
CVE-2014-0054 Spring Framework: incomplete fix for CVE-2013-7315/CVE-2013-6429
The fixes for the CVE-2013-7315 (bug 1061509) and CVE-2013-6429 (bug 1053290) XML External Entity (XXE) issues were found to be incomplete. From the original advisory:
"Spring MVC's Jaxb2RootElementHttpMessageConverter also processed user provided XML and neither disabled XML external entities nor provided an option to disable them. Jaxb2RootElementHttpMessageConverter has been modified to provide an option to control the processing of XML external entities and that processing is now disabled by default."
This issue affects versions 3.0.0 to 3.2.8, and versions 4.0.0 to 4.0.1.
External References:
http://www.gopivotal.com/security/cve-2014-0054
Discussion:
Statement:
The Red Hat Security Response Team ha
Bugzilla
CVE-2013-7315 Spring Framework: XML External Entity (XXE) injection flaw
bugzilla·2014-02-05·CVSS 6.8
CVE-2013-7315 [MEDIUM] CVE-2013-7315 Spring Framework: XML External Entity (XXE) injection flaw
CVE-2013-7315 Spring Framework: XML External Entity (XXE) injection flaw
It was found that Spring MVC processed user-provided XML with JAXB, in combination with a StAX XMLInputFactory, without disabling external entity resolution. A remote attacker could use this flaw to conduct XML External Entity (XXE) attacks on web sites, and read files in the context of the user running the application server. This flaw affects Spring Framework 3.2.x before 3.2.4 and 4.0.0.M1 through 4.0.0.M2.
Discussion:
Upstream Patch:
https://jira.springsource.org/secure/attachment/21319/Jaxb2CollectionHttpMessageConverter.patch
Statement:
Not affected. Spring MVC as shipped in various Red Hat products does not include the vulnerable org.springframework.http.converter.xml.Jaxb2CollectionHttpMessageConverter c
Bugzilla
CVE-2013-4152 Spring Framework: XML External Entity (XXE) injection flaw
bugzilla·2013-08-22·CVSS 6.8
CVE-2013-4152 [MEDIUM] CVE-2013-4152 Spring Framework: XML External Entity (XXE) injection flaw
CVE-2013-4152 Spring Framework: XML External Entity (XXE) injection flaw
It was reported [1] that the Spring Framework suffered from several XML External Entity (XXE) flaws:
Versions Affected:
- 3.0.0 to 3.2.3 (Spring OXM)
- 3.2.0 to 3.2.3 (Spring MVC)
- 4.0.0.M1 (Spring OXM)
- 4.0.0.M1-4.0.0.M2 (Spring MVC)
- Earlier unsupported versions may also be affected
Description:
The Spring OXM wrapper did not expose any property for disabling entity resolution when using the JAXB unmarshaller.
There are four possible source implementations passed to the unmarshaller:
- DOMSource
- StAXSource
- SAXSource
- StreamSource
For a DOMSource, the XML has already been parsed by user code and that code is responsible for protecting against XXE.
For a StAXSource, the XMLStreamReader has already been crea
http://seclists.org/bugtraq/2013/Aug/154http://seclists.org/fulldisclosure/2013/Nov/14http://www.debian.org/security/2014/dsa-2842http://www.gopivotal.com/security/cve-2013-4152http://www.securityfocus.com/bid/77998https://jira.springsource.org/browse/SPR-10806http://seclists.org/bugtraq/2013/Aug/154http://seclists.org/fulldisclosure/2013/Nov/14http://www.debian.org/security/2014/dsa-2842http://www.gopivotal.com/security/cve-2013-4152http://www.securityfocus.com/bid/77998https://jira.springsource.org/browse/SPR-10806
2014-01-23
Published