Access Restriction Bypass Affecting libspring-java package, versions <3.0.6.RELEASE-10


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
5.07% (92nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ECHOLATEST-LIBSPRINGJAVA-19477067
  • published1 Sept 2026
  • disclosed23 Jan 2014

Introduced: 23 Jan 2014

CVE-2013-7315  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

Upgrade Echo:latest libspring-java to version 3.0.6.RELEASE-10 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libspring-java package and not the libspring-java package as distributed by Echo. See How to fix? for Echo:latest relevant fixed versions and status.

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

CVSS Base Scores

version 3.1