CVE-2014-0225
published 2017-05-25CVE-2014-0225: When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by…
PriorityP340high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.70%
74.6th percentile
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 3.0.6.RELEASE-14 (bookworm) | libspring-java 3.0.6.RELEASE-14 (bookworm) |
| pivotal | spring_framework | — | — |
| pivotal | spring_framework | — | — |
| pivotal | spring_framework | — | — |
| pivotal_software | spring_framework | — | — |
| pivotal_software | spring_framework | — | — |
| pivotal_software | spring_framework | — | — |
| pivotal_software | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Restriction of XML External Entity Reference in Spring Framework
osv·2022-05-13
CVE-2014-0225 [HIGH] Improper Restriction of XML External Entity Reference in Spring Framework
Improper Restriction of XML External Entity Reference in Spring Framework
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
GHSA
Improper Restriction of XML External Entity Reference in Spring Framework
ghsa·2022-05-13
CVE-2014-0225 [HIGH] CWE-611 Improper Restriction of XML External Entity Reference in Spring Framework
Improper Restriction of XML External Entity Reference in Spring Framework
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
OSV
libspring-java vulnerabilities
osv·2021-03-17·CVSS 8.8
CVE-2015-3192 [HIGH] libspring-java vulnerabilities
libspring-java vulnerabilities
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of ser
OSV
CVE-2014-0225: When processing user provided XML documents, the Spring Framework 4
osv·2017-05-25·CVSS 8.8
CVE-2014-0225 [HIGH] CVE-2014-0225: When processing user provided XML documents, the Spring Framework 4
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
Ubuntu
Spring Framework vulnerabilities
vendor_ubuntu·2021-03-17·CVSS 8.8
CVE-2015-5211 [HIGH] Spring Framework vulnerabilities
Title: Spring Framework vulnerabilities
Summary: Several security issues were fixed in Spring Framework.
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this is
Red Hat
Framework: Information disclosure via SSRF
vendor_redhat·2014-05-28·CVSS 8.8
CVE-2014-0225 [HIGH] CWE-611 Framework: Information disclosure via SSRF
Framework: Information disclosure via SSRF
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
It was found that the Spring Framework did not, by default, disable the resolution of URI references in a DTD declaration when processing user-provided XML documents. By observing differences in response times, an attacker could identify valid IP addresses on the internal network with functioning web servers.
Statement: Red Hat OpenShift Enterprise 1.2 is now in Production 1 Phase of the support
and maintenance life cycle. This has been rated as having Moderate security
impact and is not currently p
Debian
CVE-2014-0225: libspring-java - When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4...
vendor_debian·2014·CVSS 8.8
CVE-2014-0225 [HIGH] CVE-2014-0225: libspring-java - When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4...
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
Scope: local
bookworm: resolved (fixed in 3.0.6.RELEASE-14)
bullseye: resolved (fixed in 3.0.6.RELEASE-14)
forky: resolved (fixed in 3.0.6.RELEASE-14)
sid: resolved (fixed in 3.0.6.RELEASE-14)
trixie: resolved (fixed in 3.0.6.RELEASE-14)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0225 Spring Framework: Information disclosure via SSRF
bugzilla·2014-06-17·CVSS 8.8
CVE-2014-0225 [HIGH] CVE-2014-0225 Spring Framework: Information disclosure via SSRF
CVE-2014-0225 Spring Framework: Information disclosure via SSRF
When processing user provided XML documents, the Spring Framework did not disable by default the resolution of URI references in a DTD declaration. By observing differences in response times, an attacker could then identify valid IP addresses on the internal network with functioning web servers.
Affects:
Spring MVC 3.0.0 to 3.2.8
Spring MVC 4.0.0 to 4.0.4
Spring OXM 3.0.0 to 3.2.8
Spring OXM 4.0.0 to 4.0.4
Upstream notes that earlier unsupported versions may be affected.
Upstream Bug Report:
https://jira.spring.io/browse/SPR-11768
Upstream Fix:
https://github.com/spring-projects/spring-framework/commit/c6503ebbf7c9e21ff022c58706dbac5417b2b5eb (3.2.9)
https://github.com/spring-projects/spring-framework/commit/8e096aeef5528
Bugzilla
CVE-2014-0225 springframework: Spring Framework: Information disclosure via SSRF [fedora-all]
bugzilla·2014-06-17·CVSS 8.8
CVE-2014-0225 [HIGH] CVE-2014-0225 springframework: Spring Framework: Information disclosure via SSRF [fedora-all]
CVE-2014-0225 springframework: Spring Framework: Information disclosure via SSRF [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue a
2017-05-25
Published