Vulnerability record · CVE-2013-6429 · published 26 January 2014
CVE-2013-6429: Spring MVC SourceHttpMessageConverter XXE enables file read and CSRF
Pivotal Software · Spring Framework
Spring MVC's SourceHttpMessageConverter in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 fails to disable external entity resolution when parsing XML. This XML External Entity (XXE) flaw lets remote attackers read arbitrary files, cause denial of service, and conduct CSRF attacks via crafted XML. It is distinct from CVE-2013-4152 and CVE-2013-7315.
Description
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityHigh EPSS probability and severe impact (file read, DoS, CSRF) despite medium CVSS and no KEV listing.
What it is
Spring MVC's SourceHttpMessageConverter in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 fails to disable external entity resolution when parsing XML. This XML External Entity (XXE) flaw lets remote attackers read arbitrary files, cause denial of service, and conduct CSRF attacks via crafted XML. It is distinct from CVE-2013-4152 and CVE-2013-7315.
Impact
An attacker can read arbitrary files accessible to the application process, trigger denial of service, and perform CSRF actions. This exposes sensitive data and can disrupt or manipulate application behavior.
Attack surface
Reached remotely over the network by submitting crafted XML to a Spring MVC endpoint that uses SourceHttpMessageConverter. No authentication is required per the CVSS vector (Au:N), though exploitation complexity is medium (AC:M) and may require some user interaction or specific conditions.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.9056 (99.8th percentile), indicating elevated likelihood of exploitation activity. References are third-party and vendor advisories without public exploit tags.
What to do
- Upgrade Spring Framework to 3.2.5 or later, or to a fixed 4.0.0 release after RC1.
- Disable external entity resolution in XML parsers used by SourceHttpMessageConverter.
- Apply vendor patches from Red Hat, Pivotal, or HPE advisories where applicable.
- Restrict file system permissions and network access for the application server to limit XXE impact.
- Validate and sanitize XML input, rejecting documents containing DOCTYPE or external entity declarations.
Detection
- Monitor application logs for XML parsing errors or outbound requests to unexpected external entities.
- Inspect HTTP requests for XML payloads containing DOCTYPE or ENTITY declarations.
- Use file integrity monitoring to detect unauthorized reads of sensitive files by the application process.
- Review network traffic for anomalous outbound connections from the application server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-6429 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-6429), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.