CVE-2011-5245

The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2012-0441.html
http://rhn.redhat.com/errata/RHSA-2012-0519.html
http://rhn.redhat.com/errata/RHSA-2012-1056.html
http://rhn.redhat.com/errata/RHSA-2012-1057.html
http://rhn.redhat.com/errata/RHSA-2012-1058.html
http://rhn.redhat.com/errata/RHSA-2012-1059.html
http://rhn.redhat.com/errata/RHSA-2012-1125.html
http://rhn.redhat.com/errata/RHSA-2014-0371.html
http://rhn.redhat.com/errata/RHSA-2014-0372.html
http://secunia.com/advisories/47832 Vendor Advisory
http://secunia.com/advisories/50084 Vendor Advisory
http://secunia.com/advisories/57716
http://secunia.com/advisories/57719
http://www.osvdb.org/78680
http://www.securityfocus.com/bid/51766
https://bugzilla.redhat.com/show_bug.cgi?id=785631
https://exchange.xforce.ibmcloud.com/vulnerabilities/72808
https://issues.jboss.org/browse/RESTEASY-647 Patch
https://issues.jboss.org/browse/RESTEASY/fixforversion/12318708
http://rhn.redhat.com/errata/RHSA-2012-0441.html
http://rhn.redhat.com/errata/RHSA-2012-0519.html
http://rhn.redhat.com/errata/RHSA-2012-1056.html
http://rhn.redhat.com/errata/RHSA-2012-1057.html
http://rhn.redhat.com/errata/RHSA-2012-1058.html
http://rhn.redhat.com/errata/RHSA-2012-1059.html
http://rhn.redhat.com/errata/RHSA-2012-1125.html
http://rhn.redhat.com/errata/RHSA-2014-0371.html
http://rhn.redhat.com/errata/RHSA-2014-0372.html
http://secunia.com/advisories/47832 Vendor Advisory
http://secunia.com/advisories/50084 Vendor Advisory
http://secunia.com/advisories/57716
http://secunia.com/advisories/57719
http://www.osvdb.org/78680
http://www.securityfocus.com/bid/51766
https://bugzilla.redhat.com/show_bug.cgi?id=785631
https://exchange.xforce.ibmcloud.com/vulnerabilities/72808
https://issues.jboss.org/browse/RESTEASY-647 Patch
https://issues.jboss.org/browse/RESTEASY/fixforversion/12318708
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:resteasy:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:1.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:2.3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:33

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2012-0441.html - () http://rhn.redhat.com/errata/RHSA-2012-0441.html -
References () http://rhn.redhat.com/errata/RHSA-2012-0519.html - () http://rhn.redhat.com/errata/RHSA-2012-0519.html -
References () http://rhn.redhat.com/errata/RHSA-2012-1056.html - () http://rhn.redhat.com/errata/RHSA-2012-1056.html -
References () http://rhn.redhat.com/errata/RHSA-2012-1057.html - () http://rhn.redhat.com/errata/RHSA-2012-1057.html -
References () http://rhn.redhat.com/errata/RHSA-2012-1058.html - () http://rhn.redhat.com/errata/RHSA-2012-1058.html -
References () http://rhn.redhat.com/errata/RHSA-2012-1059.html - () http://rhn.redhat.com/errata/RHSA-2012-1059.html -
References () http://rhn.redhat.com/errata/RHSA-2012-1125.html - () http://rhn.redhat.com/errata/RHSA-2012-1125.html -
References () http://rhn.redhat.com/errata/RHSA-2014-0371.html - () http://rhn.redhat.com/errata/RHSA-2014-0371.html -
References () http://rhn.redhat.com/errata/RHSA-2014-0372.html - () http://rhn.redhat.com/errata/RHSA-2014-0372.html -
References () http://secunia.com/advisories/47832 - Vendor Advisory () http://secunia.com/advisories/47832 - Vendor Advisory
References () http://secunia.com/advisories/50084 - Vendor Advisory () http://secunia.com/advisories/50084 - Vendor Advisory
References () http://secunia.com/advisories/57716 - () http://secunia.com/advisories/57716 -
References () http://secunia.com/advisories/57719 - () http://secunia.com/advisories/57719 -
References () http://www.osvdb.org/78680 - () http://www.osvdb.org/78680 -
References () http://www.securityfocus.com/bid/51766 - () http://www.securityfocus.com/bid/51766 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=785631 - () https://bugzilla.redhat.com/show_bug.cgi?id=785631 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/72808 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/72808 -
References () https://issues.jboss.org/browse/RESTEASY-647 - Patch () https://issues.jboss.org/browse/RESTEASY-647 - Patch
References () https://issues.jboss.org/browse/RESTEASY/fixforversion/12318708 - () https://issues.jboss.org/browse/RESTEASY/fixforversion/12318708 -

Information

Published : 2012-11-23 20:55

Updated : 2024-11-21 01:33


NVD link : CVE-2011-5245

Mitre link : CVE-2011-5245

CVE.ORG link : CVE-2011-5245


JSON object : View

Products Affected

redhat

  • resteasy
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor