6.8
CVSSv2

CVE-2014-0054

Published: 17/04/2014 Updated: 11/04/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework prior to 3.2.8 and 4.0.0 prior to 4.0.2 does not disable external entity resolution, which allows remote malicious users to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

springsource spring framework 3.2.6

springsource spring framework 3.2.5

vmware spring framework 3.1.2

vmware spring framework 3.1.1

springsource spring framework 3.0.2

vmware spring framework 4.0.0

springsource spring framework 4.0.0

vmware spring framework 3.2.2

vmware spring framework 3.2.1

vmware spring framework 3.0.6

springsource spring framework 3.0.5

springsource spring framework 3.0.0

vmware spring framework 3.2.4

vmware spring framework 3.2.3

vmware spring framework 3.1.0

vmware spring framework 3.0.7

springsource spring framework 3.0.0.m2

springsource spring framework 3.0.0.m1

springsource spring framework 4.0.1

vmware spring framework

vmware spring framework 3.2.0

vmware spring framework 3.1.4

vmware spring framework 3.1.3

springsource spring framework 3.0.4

springsource spring framework 3.0.3

springsource spring framework 3.0.1

Vendor Advisories

Debian Bug report logs - #741604 libspring-java: Multiple security issues Package: libspring-java; Maintainer for libspring-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 14 Mar 2014 12:39:01 UTC Owned by: Miguel Landaeta < ...
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 328 and 400 before 402 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue NOTE: this vulnerability exis ...