PT-2014-5356 · Red Hat+2 · Resteasy+4

Ron Sigal

·

Publicado

2014-08-06

·

Atualizado

2022-05-14

·

CVE-2014-3490

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform (EAP) version 6.3.0 RESTEasy versions 2.3.1 through 2.3.8.SP2 RESTEasy versions 3.x through 3.0.9
Description The issue is related to an XML External Entity (XXE) problem, where external entities are not disabled even when the resteasy.document.expand.entity.references parameter is set to false. This allows remote attackers to read arbitrary files and potentially have other impacts via unspecified vectors.
Recommendations For RESTEasy versions 2.3.1 through 2.3.8.SP2, update to version 2.3.8.SP2 or later. For RESTEasy versions 3.x through 3.0.9, update to version 3.0.9 or later. For Red Hat JBoss Enterprise Application Platform (EAP) version 6.3.0, consider updating the embedded RESTEasy component to a fixed version. As a temporary workaround, consider setting the resteasy.document.expand.entity.references parameter to true to disable external entity expansion until a patch is available.

Correção

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2491
CESA-2014_1011
CVE-2014-3490
GHSA-QJPQ-5PQ3-43RR
MGASA-2014-0547
RHSA-2014:1011
RHSA-2014:1040
RHSA-2014_1011

Produtos afetados

Alt Linux
Centos
Resteasy
Red Hat
Red Hat Jboss Enterprise Application Platform