PT-2014-8306 · Red Hat · Resteasy
Published
2014-11-25
·
Updated
2022-05-17
·
CVE-2014-7839
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
RESTEasy versions 2.3.7 through 3.0.9
Description
The issue allows remote attackers to conduct XML external entity (XXE) attacks. This is due to the DocumentProvider in RESTEasy not configuring the external-general-entities or external-parameter-entities features.
Recommendations
For versions 2.3.7 through 3.0.9, consider disabling the DocumentProvider until a patch is available to prevent XXE attacks. Restrict access to sensitive data and external entities to minimize the risk of exploitation.
Fix
RCE
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Resteasy