Lucene search

K
cve[email protected]CVE-2013-6429
HistoryJan 26, 2014 - 4:58 p.m.

CVE-2013-6429

2014-01-2616:58:10
CWE-352
CWE-611
web.nvd.nist.gov
103
cve-2013-6429
sourcehttpmessageconverter
spring mvc
spring framework
xxe
xml external entity
denial of service
csrf
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

5.7 Medium

AI Score

Confidence

High

0.937 High

EPSS

Percentile

99.1%

The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.

Affected configurations

NVD
Node
pivotal_softwarespring_frameworkRange3.0.03.2.4
OR
vmwarespring_frameworkMatch4.0.0milestone1
OR
vmwarespring_frameworkMatch4.0.0milestone2
OR
vmwarespring_frameworkMatch4.0.0rc1

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

5.7 Medium

AI Score

Confidence

High

0.937 High

EPSS

Percentile

99.1%