PT-2014-5375 · Jboss · Picketlink
Published
2014-07-22
·
Updated
2023-02-13
·
CVE-2014-3530
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PicketLink versions 5.2.0 through 6.2.4
Description
The issue is related to an XML External Entity (XXE) problem, where the
org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink expands entity references. This allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified vectors.Recommendations
For versions 5.2.0 through 6.2.4, consider disabling the
org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method as a temporary workaround until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation.Fix
XXE
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Picketlink