← Back

CVE-2013-7315

nvd nist
Published: Jan 23, 2014Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

Affected (28)

1 product
Spring Framework
1 product
Spring Framework
Configuration A
28 vulnerable
Vulnerable SoftwareAffected Versions
Springsource
Version 3.0.0.m1
Version 3.0.0.m2
Version 3.0.0
Version 3.0.0 m1
Version 3.0.0 m2
Version 3.0.0 m3
Version 3.0.0 m4
Version 3.0.0 rc1
Version 3.0.0 rc2
Version 3.0.0 rc3
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5
Vmware
Up to 3.2.3
Version 3.0.6
Version 3.0.7
Version 3.1.0
Version 3.1.1
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.2.0
Version 3.2.1
Version 3.2.2
Version 4.0.0 milestone1
Version 4.0.0 milestone2

Related CWEs

References (12)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch

Timeline

No history available yet.