CVE Database
/

CVE-2013-7315

Back to search

CVE-2013-7315

Published: Jan 23, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

VendorProductVersions

n/a

n/a

affected
n/a

References

20131102 XXE Injection in Spring Framework
mailing-list
x_refsource_FULLDISC
DSA-2842
vendor-advisory
x_refsource_DEBIAN
77998
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now