CVE-2013-1915
Last modified
CVE-2013-1915 is a vulnerability of currently unknown severity. ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.. EPSS estimates a 4.21% chance of exploitation in the next 30 days.
Description
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trustwave | Modsecurity | < 2.7.3 |
| Opensuse | Opensuse | 11.4 |
| Opensuse | Opensuse | 12.2 |
| Opensuse | Opensuse | 12.3 |
| Fedoraproject | Fedora | 17 |
| Fedoraproject | Fedora | 18 |
| Fedoraproject | Fedora | 19 |
| Debian | Debian Linux | 6.0 |
| Debian | Debian Linux | 7.0 |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101898.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101911.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102616.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00020.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00025.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00031.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/52847Third Party Advisory
- http://secunia.com/advisories/52977Third Party Advisory
- http://www.debian.org/security/2013/dsa-2659Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:156Third Party Advisory
- http://www.openwall.com/lists/oss-security/2013/04/03/7Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/58810Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=947842Issue Tracking, Patch, Third Party Advisory
- https://github.com/SpiderLabs/ModSecurity/blob/master/CHANGESRelease Notes, Third Party Advisory
- https://github.com/SpiderLabs/ModSecurity/commit/d4d80b38aa85eccb26e3c61b04d16e8ca5de76fePatch, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101898.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101911.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102616.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00020.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00025.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00031.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/52847Third Party Advisory
- http://secunia.com/advisories/52977Third Party Advisory
- http://www.debian.org/security/2013/dsa-2659Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:156Third Party Advisory
- http://www.openwall.com/lists/oss-security/2013/04/03/7Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/58810Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=947842Issue Tracking, Patch, Third Party Advisory
- https://github.com/SpiderLabs/ModSecurity/blob/master/CHANGESRelease Notes, Third Party Advisory
- https://github.com/SpiderLabs/ModSecurity/commit/d4d80b38aa85eccb26e3c61b04d16e8ca5de76fePatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1915?
How severe is CVE-2013-1915?
How do I fix CVE-2013-1915?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-1909The Python client in Apache Qpid before 2.2 does not verify …
- CVE-2013-1910yum does not properly handle bad metadata, which allows an a…9.8
- CVE-2013-1911lib/ldoce/word.rb in the ldoce 0.0.2 gem for Ruby allows rem…
- CVE-2013-1912Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev th…
- CVE-2013-1913Integer overflow in the load_image function in file-xwd.c in…
- CVE-2013-1914Stack-based buffer overflow in the getaddrinfo function in s…
- CVE-2013-1916In WordPress Plugin User Photo 0.9.4, when a photo is upload…8.8
- CVE-2013-1917Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs…
- CVE-2013-1918Certain page table manipulation operations in Xen 4.1.x, 4.2…
- CVE-2013-1919Xen 4.2.x and 4.1.x does not properly restrict access to IRQ…
- CVE-2013-1920Xen 4.2.x, 4.1.x, and earlier, when the hypervisor is runnin…
- CVE-2013-1921PicketBox, as used in Red Hat JBoss Enterprise Application P…
Are you affected by CVE-2013-1915?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
