Back

MEDIUM

Framework: XML External Entity (XXE) injection flaw

Published Jan 26, 2014

Description

The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 26, 2014
Updated Aug 6, 2024
Reserved Nov 4, 2013
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 14, 2014
GHSA-G6HF-F9CQ-Q7W7