Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-7839

Опубликовано: 25 нояб. 2014
Источник: nvd
CVSS2: 6.4
EPSS Низкий

Описание

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:resteasy:2.3.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:3.0.9:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01955
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 11 лет назад

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

redhat
больше 11 лет назад

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

debian
больше 11 лет назад

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1 ...

github
около 4 лет назад

XML External Entity Reference in RESTEasy

EPSS

Процентиль: 78%
0.01955
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-20