Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2014-0054

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
springsource / spring_framework 3.0.0-m2 3.0.0-m2.x
springsource / spring_framework 3.0.1 3.0.1.x
springsource / spring_framework 3.0.0-rc3 3.0.0-rc3.x
springsource / spring_framework 3.0.5 3.0.5.x
springsource / spring_framework 4.0.0-rc1 4.0.0-rc1.x
springsource / spring_framework 3.0.2 3.0.2.x
springsource / spring_framework 3.0.0-m3 3.0.0-m3.x
springsource / spring_framework 3.0.0-rc2 3.0.0-rc2.x
springsource / spring_framework 3.0.0-m1 3.0.0-m1.x
springsource / spring_framework 4.0.1 4.0.1.x
springsource / spring_framework 3.0.4 3.0.4.x
springsource / spring_framework 3.0.0-rc1 3.0.0-rc1.x
springsource / spring_framework 3.0.3 3.0.3.x
springsource / spring_framework 3.2.5 3.2.5.x
springsource / spring_framework 3.0.0.m1 3.0.0.m1.x
springsource / spring_framework 3.0.0-m4 3.0.0-m4.x
springsource / spring_framework 3.2.6 3.2.6.x
springsource / spring_framework 3.0.0 3.0.0.x
springsource / spring_framework 3.0.0.m2 3.0.0.m2.x
vmware / spring_framework 3.2.2 3.2.2.x
vmware / spring_framework 3.2.1 3.2.1.x
vmware / spring_framework 3.2.4 3.2.4.x
vmware / spring_framework 3.2.3 3.2.3.x
vmware / spring_framework 3.0.7 3.0.7.x
vmware / spring_framework 3.0.6 3.0.6.x
vmware / spring_framework 3.1.4 3.1.4.x
vmware / spring_framework 3.1.1 3.1.1.x
vmware / spring_framework 3.1.3 3.1.3.x
vmware / spring_framework 3.1.2 3.1.2.x
vmware / spring_framework 4.0.0-milestone2 4.0.0-milestone2.x
vmware / spring_framework 4.0.0-milestone1 4.0.0-milestone1.x
vmware / spring_framework - 3.2.7.x
vmware / spring_framework 3.2.0 3.2.0.x
vmware / spring_framework 3.1.0 3.1.0.x
org.springframework / spring-webmvc - 3.2.8
org.springframework / spring-webmvc 4.0.0 4.0.2