CVE-2013-4152
Last modified
CVE-2013-4152 is a vulnerability of currently unknown severity. The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.. EPSS estimates a 26.27% chance of exploitation in the next 30 days.
Description
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Springsource | Spring Framework | 3.0.0 | — |
| Springsource | Spring Framework | 3.0.0.m1 | — |
| Springsource | Spring Framework | 3.0.0.m2 | — |
| Springsource | Spring Framework | 3.0.1 | — |
| Springsource | Spring Framework | 3.0.2 | — |
| Springsource | Spring Framework | 3.0.3 | — |
| Springsource | Spring Framework | 3.0.4 | — |
| Springsource | Spring Framework | 3.0.5 | — |
| Vmware | Spring Framework | <= 3.2.3 | — |
| Vmware | Spring Framework | 3.0.6 | — |
| Vmware | Spring Framework | 3.0.7 | — |
| Vmware | Spring Framework | 3.1.0 | — |
| Vmware | Spring Framework | 3.1.1 | — |
| Vmware | Spring Framework | 3.1.2 | — |
| Vmware | Spring Framework | 3.1.3 | — |
| Vmware | Spring Framework | 3.1.4 | — |
| Vmware | Spring Framework | 3.2.0 | — |
| Vmware | Spring Framework | 3.2.1 | — |
| Vmware | Spring Framework | 3.2.2 | — |
| Vmware | Spring Framework | 4.0.0 | Milestone1 |
References
- http://www.gopivotal.com/security/cve-2013-4152Vendor Advisory
- https://jira.springsource.org/browse/SPR-10806Exploit, Patch
- http://www.gopivotal.com/security/cve-2013-4152Vendor Advisory
- https://jira.springsource.org/browse/SPR-10806Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4152?
How severe is CVE-2013-4152?
How do I fix CVE-2013-4152?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-4146Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-4147Multiple format string vulnerabilities in Yet Another Radius…
- CVE-2013-4148Integer signedness error in the virtio_net_load function in …
- CVE-2013-4149Buffer overflow in virtio_net_load function in net/virtio-ne…
- CVE-2013-4150The virtio_net_load function in hw/net/virtio-net.c in QEMU …
- CVE-2013-4151The virtio_load function in virtio/virtio.c in QEMU 1.x befo…
- CVE-2013-4153Double free vulnerability in the qemuAgentGetVCPUs function …
- CVE-2013-4154The qemuAgentCommand function in libvirt before 1.1.1, when …
- CVE-2013-4155OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana …
- CVE-2013-4156Apache OpenOffice.org (OOo) before 4.0 allows remote attacke…
- CVE-2013-4157Red Hat Storage 2.0 allows local users to overwrite arbitrar…
- CVE-2013-4158smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-…6.1
Are you affected by CVE-2013-4152?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
