← All CVEs

CVE-2013-4152

medium · 6.8

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.

6.8
CVSS
25.5%
EPSS (exploit prob.)
98th
EPSS percentile
2014-01-23
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
springsourcespring_framework3.0.0
springsourcespring_framework3.0.0
springsourcespring_framework3.0.0
springsourcespring_framework3.0.0
springsourcespring_framework3.0.0
springsourcespring_framework3.0.0
springsourcespring_framework3.0.0
springsourcespring_framework3.0.0
springsourcespring_framework3.0.0.m1
springsourcespring_framework3.0.0.m2
springsourcespring_framework3.0.1
springsourcespring_framework3.0.2
springsourcespring_framework3.0.3
springsourcespring_framework3.0.4
springsourcespring_framework3.0.5
vmwarespring_framework<= 3.2.3
vmwarespring_framework3.0.6
vmwarespring_framework3.0.7
vmwarespring_framework3.1.0
vmwarespring_framework3.1.1
vmwarespring_framework3.1.2
vmwarespring_framework3.1.3
vmwarespring_framework3.1.4
vmwarespring_framework3.2.0
vmwarespring_framework3.2.1
vmwarespring_framework3.2.2
vmwarespring_framework4.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-4152