Release date:
Updated on:
Affected Systems:
SpringSource Spring Framework 3.0.0-3.0.2
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-4152
Spring Framework is an open-source Java/Java EE full-stack application Framework released in the form of an Apache license, and also has a portable version on the. NET platform.
An error occurs when Spring Framework 3.0.0-3.2.3 processes specially crafted XML data that contains external entity references. Attackers can exploit this vulnerability to expose the content of some local files.
<* Source: Alvaro Munoz
Link: http://secunia.com/advisories/54492/
Http://www.gopivotal.com/security/cve-2013-4152
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SpringSource
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.springsource.com/security/