Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7839

Опубликовано: 18 нояб. 2014
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

It was found that the RESTEasy DocumentProvider did not set the external-parameter-entities and external-general-entities features appropriately, thus allowing external entity expansion. A remote attacker able to send XML requests to a RESTEasy endpoint could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XML eXternal Entity (XXE) attacks.

Отчет

Red Hat Web Framework Kit has moved out of maintenance phase and is no longer supported by Red Hat Product Security. This issue is not currently planned to be addressed in any future updates. For additional information, refer to the Red Hat JBoss Middleware Product Update and Support Policy: https://access.redhat.com/support/policy/updates/jboss_notes/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7resteasy-baseAffected
Red Hat JBoss BRMS 5resteasyWill not fix
Red Hat JBoss Data Virtualization 6resteasyAffected
Red Hat JBoss Enterprise Application Platform 5resteasyWill not fix
Red Hat JBoss Enterprise Web Server 1ewp-5Will not fix
Red Hat JBoss Fuse Service Works 6resteasyAffected
Red Hat JBoss Operations Network 3resteasyAffected
Red Hat JBoss Portal 5resteasyWill not fix
Red Hat JBoss Portal 6resteasyAffected
Red Hat JBoss SOA Platform 5resteasyWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1165328RESTeasy: External entities expanded by DocumentProvider

EPSS

Процентиль: 79%
0.01262
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

nvd
около 11 лет назад

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

debian
около 11 лет назад

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1 ...

github
больше 3 лет назад

XML External Entity Reference in RESTEasy

EPSS

Процентиль: 79%
0.01262
Низкий

5 Medium

CVSS2

Уязвимость CVE-2014-7839