PT-2014-5356 · Red Hat+2 · Resteasy+4
Ron Sigal
·
Publicado
2014-08-06
·
Atualizado
2022-05-14
·
CVE-2014-3490
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat JBoss Enterprise Application Platform (EAP) version 6.3.0
RESTEasy versions 2.3.1 through 2.3.8.SP2
RESTEasy versions 3.x through 3.0.9
Description
The issue is related to an XML External Entity (XXE) problem, where external entities are not disabled even when the
resteasy.document.expand.entity.references parameter is set to false. This allows remote attackers to read arbitrary files and potentially have other impacts via unspecified vectors.Recommendations
For RESTEasy versions 2.3.1 through 2.3.8.SP2, update to version 2.3.8.SP2 or later.
For RESTEasy versions 3.x through 3.0.9, update to version 3.0.9 or later.
For Red Hat JBoss Enterprise Application Platform (EAP) version 6.3.0, consider updating the embedded RESTEasy component to a fixed version.
As a temporary workaround, consider setting the
resteasy.document.expand.entity.references parameter to true to disable external entity expansion until a patch is available.Correção
Incorrect Privilege Assignment
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Resteasy
Red Hat
Red Hat Jboss Enterprise Application Platform