Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:SPRING-XMLENTITY-INFODISC

Severity

Minor

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

SpringSource Spring Framework XML External Entity Parsing Information Disclosure

Release Date

2013/10/24

Update Number

2313

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: SpringSource Spring Framework XML External Entity Parsing Information Disclosure


This signature detects attempts to exploit a know vulnerability against SpringSource Spring Framework. The vulnerability is due to incorrectly configured XML parsing which accepts XML external entities from untrusted sources. A remote, unauthenticated attacker can leverage this vulnerability by sending a malicious request to the target server. Successful exploitation would result in the disclosure of information from arbitrary files available to the security context of the server application.

Extended Description

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.

Affected Products

  • Springsource spring_framework 3.0.0
  • Springsource spring_framework 3.0.0.m1
  • Springsource spring_framework 3.0.0.m2
  • Springsource spring_framework 3.0.1
  • Springsource spring_framework 3.0.2
  • Springsource spring_framework 3.0.3
  • Springsource spring_framework 3.0.4
  • Springsource spring_framework 3.0.5
  • Springsource spring_framework 3.0.6
  • Springsource spring_framework 3.0.7
  • Springsource spring_framework 3.1.0
  • Springsource spring_framework 3.1.1
  • Springsource spring_framework 3.1.2
  • Springsource spring_framework 3.1.3
  • Springsource spring_framework 3.1.4
  • Springsource spring_framework 3.2.0
  • Springsource spring_framework 3.2.1
  • Springsource spring_framework 3.2.2
  • Springsource spring_framework 3.2.3
  • Springsource spring_framework 4.0.0

References

  • BugTraq: 61951
  • CVE: CVE-2013-4152

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out