CVE-2014-3599

Severity
6.5MEDIUM
EPSS
0.4%
top 40.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

Mavenorg.hornetq.rest:hornetq-rest< 2.5.0.Beta1
CVEListV5hornetq_rest/hornetq_restFixed In Version: 2.5.0
NVDredhat/hornetq2.4.5

Patches

🔴Vulnerability Details

3
OSV
HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference2022-05-24
GHSA
HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference2022-05-24
CVEList
CVE-2014-3599: HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy2019-11-12

📋Vendor Advisories

1
Red Hat
REST: XXE due to insecure configuration of RestEasy2014-11-18

💬Community

1
Bugzilla
CVE-2014-3599 HornetQ REST: XXE due to insecure configuration of RestEasy2014-08-15
CVE-2014-3599 (MEDIUM CVSS 6.5) | HornetQ REST is vulnerable to XML E | cvebase.io