CVE-2013-4152
EPSS 68.0%libspring-java - several
發布日:2022/5/13修改日:2026/4/28
描述
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
受影響套件(3)
- Debian/libspring-javafrom 0, < 3.0.6.RELEASE-10
- Debian/libspring-javafrom 0, < 3.0.6.RELEASE-6+deb7u1
- Maven/org.springframework:spring-oxmfrom 0, < 3.2.4.RELEASE
參考連結(13)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2013-4152
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2013-4152
- WEBhttp://rhn.redhat.com/errata/RHSA-2014-0212.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2014-0245.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2014-0254.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2014-0400.html
- WEBhttp://seclists.org/bugtraq/2013/Aug/154
- WEBhttp://seclists.org/fulldisclosure/2013/Nov/14
- WEBhttps://github.com/spring-projects/spring-framework/commit/434735fbf6e7f9051af2ef027657edb99120b173
- WEBhttps://github.com/spring-projects/spring-framework/commit/7576274874deeccb6da6b09a8d5bd62e8b5538b7
- WEBhttps://github.com/spring-projects/spring-framework/pull/317/files
- WEBhttp://www.debian.org/security/2014/dsa-2842
- WEBhttp://www.gopivotal.com/security/cve-2013-4152