CVE-2013-1915: Debian Linux

High severity, CVSS 7.5. EPSS: 4.2% chance of exploitation in the next 30 days.

ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.

Affected products

  • Debian Debian Linux: version 6.0 only; version 7.0 only
  • Fedoraproject Fedora: version 17 only; version 18 only; version 19 only
  • Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
  • Trustwave Modsecurity: before 2.7.3 (fixed in 2.7.3)

Published 2013-04-25. Last modified 2026-06-16.