AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2014-0054

MEDIUM · CVSS 6.8 EPSS 91.35%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-04-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2014-0054
Severity
MEDIUM
CVSS
6.8
EPSS
91.35%

Original NVD Description

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.