Back to search
CVE-2013-6429
Published: Jan 26, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20140114 CVE-2013-6429 Fix for XML External Entity (XXE) injection (CVE-2013-4152) in Spring Framework was incomplete
mailing-list
x_refsource_BUGTRAQ
http://www.gopivotal.com/security/cve-2013-6429
x_refsource_CONFIRM
RHSA-2014:0400
vendor-advisory
x_refsource_REDHAT
64947
vdb-entry
x_refsource_BID
57915
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now