Summary
Detail | |||
---|---|---|---|
Vendor | Springsource | First view | 2014-04-17 |
Product | Spring Framework | Last view | 2014-04-17 |
Version | 4.0.1 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:springsource:spring_framework |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
6.8 | 2014-04-17 | CVE-2014-0054 | The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
100% (1) | CWE-352 | Cross-Site Request Forgery (CSRF) |
Snort® IPS/IDS
Date | Description |
---|---|
2017-08-03 | XML entity parsing information disclosure attempt RuleID : 43444 - Type : SERVER-WEBAPP - Revision : 2 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2014-03-31 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-2890.nasl - Type: ACT_GATHER_INFO |