CVE-2014-3599
published 2019-11-12CVE-2014-3599: HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.20%
64.7th percentile
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hornetq_rest | hornetq_rest | — | — |
| redhat | hornetq | <= 2.4.5 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference
osv·2022-05-24
CVE-2014-3599 [MEDIUM] HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference
HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy.
GHSA
HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference
ghsa·2022-05-24
CVE-2014-3599 [MEDIUM] CWE-611 HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference
HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy.
Red Hat
REST: XXE due to insecure configuration of RestEasy
vendor_redhat·2014-11-18·CVSS 6.5
CVE-2014-3599 [MEDIUM] CWE-611 REST: XXE due to insecure configuration of RestEasy
REST: XXE due to insecure configuration of RestEasy
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
It was discovered that HornetQ REST did not set the resteasy.document.expand.entity.references context parameter to false by default. A HornetQ REST application, which does not explicitly set the required context parameter to false, may be vulnerable to XML External Entity (XXE) attacks. A remote attacker able to send XML requests to a HornetQ REST endpoint could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Statement: Not Vulnerable. HornetQ REST is not provided by any Red Hat product.
Mitigation: When using HornetQ REST in an application, add the fol
No detection rules found.
No public exploits indexed.
2019-11-12
Published