Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-5245

Опубликовано: 30 дек. 2011
Источник: redhat
CVSS2: 5

Описание

The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5SecurityAffected
Red Hat JBoss Data Virtualization 6TeiidAffected
Red Hat JBoss SOA Platform 5SecurityAffected
Red Hat Storage 2.1resteasyAffected
JBEWP 5 for RHEL 5resteasyFixedRHSA-2012:105805.07.2012
JBEWP 5 for RHEL 6resteasyFixedRHSA-2012:105805.07.2012
JBoss Enterprise BRMS Platform 5.2FixedRHSA-2012:044102.04.2012
Red Hat JBoss BPMS 6.0securityFixedRHSA-2014:037103.04.2014
Red Hat JBoss BRMS 6.0securityFixedRHSA-2014:037203.04.2014
Red Hat JBoss Enterprise Application Platform 5.1FixedRHSA-2012:105605.07.2012

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=785631RESTEasy: XML eXternal Entity (XXE) flaw

5 Medium

CVSS2

Связанные уязвимости

nvd
около 13 лет назад

The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.

github
больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy

5 Medium

CVSS2