This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Springsource First view 2014-04-17
Product Spring Framework Last view 2014-04-17
Version 4.0.1 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:springsource:spring_framework

Activity : Overall

Related : CVE

  Date Alert Description
6.8 2014-04-17 CVE-2014-0054

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-352 Cross-Site Request Forgery (CSRF)

Snort® IPS/IDS

Date Description
2017-08-03 XML entity parsing information disclosure attempt
RuleID : 43444 - Type : SERVER-WEBAPP - Revision : 2

Nessus® Vulnerability Scanner

id Description
2014-03-31 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-2890.nasl - Type: ACT_GATHER_INFO