CVE-2013-7315

N/A Unknown
Published: January 23, 2014 Modified: April 29, 2026
View on NVD

Description

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.gopivotal.com/security/cve-2013-4152
Source: cve@mitre.org
Vendor Advisory
https://jira.springsource.org/browse/SPR-10806
Source: cve@mitre.org
Exploit Patch
http://seclists.org/bugtraq/2013/Aug/154
Source: af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2013/Nov/14
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2014/dsa-2842
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.gopivotal.com/security/cve-2013-4152
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securityfocus.com/bid/77998
Source: af854a3a-2127-422b-91ae-364da2661108
https://jira.springsource.org/browse/SPR-10806
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Patch

12 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.2%
48th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

vmware springsource