Severity
5.0MEDIUM
EPSS
0.9%
top 23.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 23
Latest updateMay 17

Description

The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy2022-05-17
OSV
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy2022-05-17
CVEList
CVE-2011-5245: The readFrom function in providers2012-11-23

📋Vendor Advisories

1
Red Hat
RESTEasy: XML eXternal Entity (XXE) flaw2011-12-30

💬Community

1
Bugzilla
CVE-2011-5245 CVE-2012-0818 RESTEasy: XML eXternal Entity (XXE) flaw2012-01-30