CVE-2014-7839
published 2014-11-25CVE-2014-7839: DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows…
PriorityP337medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
1.96%
78.0th percentile
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | resteasy | < resteasy 3.0.6-2 (sid) | resteasy 3.0.6-2 (sid) |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
XML External Entity Reference in RESTEasy
osv·2022-05-17
CVE-2014-7839 [MEDIUM] XML External Entity Reference in RESTEasy
XML External Entity Reference in RESTEasy
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
GHSA
XML External Entity Reference in RESTEasy
ghsa·2022-05-17
CVE-2014-7839 [MEDIUM] CWE-20 XML External Entity Reference in RESTEasy
XML External Entity Reference in RESTEasy
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
Red Hat
RESTeasy: External entities expanded by DocumentProvider
vendor_redhat·2014-11-18·CVSS 6.4
CVE-2014-7839 [MEDIUM] CWE-611 RESTeasy: External entities expanded by DocumentProvider
RESTeasy: External entities expanded by DocumentProvider
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
It was found that the RESTEasy DocumentProvider did not set the external-parameter-entities and external-general-entities features appropriately, thus allowing external entity expansion. A remote attacker able to send XML requests to a RESTEasy endpoint could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XML eXternal Entity (XXE) attacks.
Statement: Red Hat Web Framework Kit has moved out of maintenance phase and
Debian
CVE-2014-7839: resteasy - DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external...
vendor_debian·2014·CVSS 6.4
CVE-2014-7839 [MEDIUM] CVE-2014-7839: resteasy - DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external...
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
Scope: local
sid: resolved (fixed in 3.0.6-2)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0773.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://secunia.com/advisories/62580https://issues.jboss.org/browse/RESTEASY-1130http://rhn.redhat.com/errata/RHSA-2015-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0773.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://secunia.com/advisories/62580https://issues.jboss.org/browse/RESTEASY-1130
2014-11-25
Published