Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vp63-rrcm-9mph

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Missing XML Validation in Spring Framework

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

Пакеты

Наименование

org.springframework:spring-oxm

maven
Затронутые версииВерсия исправления

<= 3.2.3.RELEASE

3.2.4.RELEASE

EPSS

Процентиль: 66%
0.00524
Низкий

Дефекты

CWE-112

Связанные уязвимости

ubuntu
больше 11 лет назад

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

redhat
больше 11 лет назад

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

nvd
больше 11 лет назад

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

debian
больше 11 лет назад

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4 ...

EPSS

Процентиль: 66%
0.00524
Низкий

Дефекты

CWE-112