Spring Framework CVE-2014-0054 Multiple XML External Entity Injection Vulnerabilities
BID:66148
Info
Spring Framework CVE-2014-0054 Multiple XML External Entity Injection Vulnerabilities
| Bugtraq ID: | 66148 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-0054 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2014 12:00AM |
| Updated: | Oct 26 2016 05:08AM |
| Credit: | Spase Markovski |
| Vulnerable: |
Redhat JBoss Fuse 6.0.0 Redhat JBoss A-MQ 6.0.0 IBM Websphere Portal 8.5 IBM Websphere Portal 8.0 IBM Websphere Portal 8.0.0.1 GoPivotal Spring Framework (Spring MVC) 4.0.1 GoPivotal Spring Framework (Spring MVC) 4.0 GoPivotal Spring Framework (Spring MVC) 3.2.7 GoPivotal Spring Framework (Spring MVC) 3.2.6 GoPivotal Spring Framework (Spring MVC) 3.2.5 GoPivotal Spring Framework (Spring MVC) 4.0.0.RC2 GoPivotal Spring Framework (Spring MVC) 4.0.0.RC1 GoPivotal Spring Framework (Spring MVC) 4.0.0.M2 GoPivotal Spring Framework (Spring MVC) 4.0.0.M1 GoPivotal Spring Framework (Spring MVC) 3.2.4 GoPivotal Spring Framework (Spring MVC) 3.2.3 GoPivotal Spring Framework (Spring MVC) 3.2.2 GoPivotal Spring Framework (Spring MVC) 3.2.1 GoPivotal Spring Framework (Spring MVC) 3.0.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Redhat JBoss Fuse 6.1.0 Redhat JBoss A-MQ 6.1.0 GoPivotal Spring Framework (Spring MVC) 4.0.2 GoPivotal Spring Framework (Spring MVC) 3.2.8 |
Discussion
Spring Framework CVE-2014-0054 Multiple XML External Entity Injection Vulnerabilities
Spring Framework is prone to multiple XML External Entity injection vulnerabilities.
Attackers can exploit these issues to obtain potentially sensitive information. This may lead to further attacks.
The following versions are vulnerable:
Spring MVC 3.0.0 through 3.2.7
Spring MVC 4.0.0 through 4.0.1
Note: This issue is the result of an incomplete fixes for the issues described in BID 61951 (Spring Framework CVE-2013-4152 Multiple XML External Entity Injection Vulnerabilities) and BID 64947 (Spring Framework CVE-2013-6429 Multiple XML External Entity Injection Vulnerabilities).
Spring Framework is prone to multiple XML External Entity injection vulnerabilities.
Attackers can exploit these issues to obtain potentially sensitive information. This may lead to further attacks.
The following versions are vulnerable:
Spring MVC 3.0.0 through 3.2.7
Spring MVC 4.0.0 through 4.0.1
Note: This issue is the result of an incomplete fixes for the issues described in BID 61951 (Spring Framework CVE-2013-4152 Multiple XML External Entity Injection Vulnerabilities) and BID 64947 (Spring Framework CVE-2013-6429 Multiple XML External Entity Injection Vulnerabilities).
Exploit / POC
Spring Framework CVE-2014-0054 Multiple XML External Entity Injection Vulnerabilities
An attacker can exploit these issues using a web browser.
An attacker can exploit these issues using a web browser.
Solution / Fix
Spring Framework CVE-2014-0054 Multiple XML External Entity Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Spring Framework CVE-2014-0054 Multiple XML External Entity Injection Vulnerabilities
References:
References:
- Add processExternalEntities support to OXM (github)
- Bug 1075328 - (CVE-2014-0054) CVE-2014-0054 Spring Framework: incomplete fix for (bugzilla)
- CVE-2014-0054 INCOMPLETE FIX FOR CVE-2013-4152 / CVE-2013-6429 (XXE) (gopivotal)
- Jaxb2RootElementHttpMessageConverter is susceptible to XXE vulnerability (spring)
- Spring Framework Homepage (Spring)
- Red Hat JBoss A-MQ 6.1.0 update (Red Hat)
- Red Hat JBoss Fuse 6.1.0 update (Red Hat)
- swg21989676: Security Bulletin: Security Vulnerabilities in Spring Framework aff (IBM)