CVE-2014-3490

RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0818.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2014-1011.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-1039.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-1040.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-1298.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0125.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0675.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0720.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0765.html Third Party Advisory
http://secunia.com/advisories/60019 Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html Patch Third Party Advisory
http://www.securityfocus.com/bid/69058 Third Party Advisory VDB Entry
https://github.com/resteasy/Resteasy/pull/521 Third Party Advisory
https://github.com/resteasy/Resteasy/pull/533 Third Party Advisory
https://github.com/ronsigal/Resteasy/commit/9b7d0f574cafdcf3bea5428f3145ab4908fc6d83 Patch Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-1011.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-1039.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-1040.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-1298.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0125.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0675.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0720.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0765.html Third Party Advisory
http://secunia.com/advisories/60019 Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html Patch Third Party Advisory
http://www.securityfocus.com/bid/69058 Third Party Advisory VDB Entry
https://github.com/resteasy/Resteasy/pull/521 Third Party Advisory
https://github.com/resteasy/Resteasy/pull/533 Third Party Advisory
https://github.com/ronsigal/Resteasy/commit/9b7d0f574cafdcf3bea5428f3145ab4908fc6d83 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:3.0:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:3.0:beta2:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:3.0:beta3:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:3.0:beta4:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:3.0:beta5:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:3.0:beta6:*:*:*:*:*:*
cpe:2.3:a:redhat:resteasy:3.0:rc1:*:*:*:*:*:*

History

21 Nov 2024, 02:08

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2014-1011.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-1011.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2014-1039.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-1039.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2014-1040.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-1040.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2014-1298.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-1298.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2015-0125.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2015-0125.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2015-0675.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2015-0675.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2015-0720.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2015-0720.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2015-0765.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2015-0765.html - Third Party Advisory
References () http://secunia.com/advisories/60019 - Third Party Advisory () http://secunia.com/advisories/60019 - Third Party Advisory
References () http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html - Patch, Third Party Advisory () http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html - Patch, Third Party Advisory
References () http://www.securityfocus.com/bid/69058 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/69058 - Third Party Advisory, VDB Entry
References () https://github.com/resteasy/Resteasy/pull/521 - Third Party Advisory () https://github.com/resteasy/Resteasy/pull/521 - Third Party Advisory
References () https://github.com/resteasy/Resteasy/pull/533 - Third Party Advisory () https://github.com/resteasy/Resteasy/pull/533 - Third Party Advisory
References () https://github.com/ronsigal/Resteasy/commit/9b7d0f574cafdcf3bea5428f3145ab4908fc6d83 - Patch, Third Party Advisory () https://github.com/ronsigal/Resteasy/commit/9b7d0f574cafdcf3bea5428f3145ab4908fc6d83 - Patch, Third Party Advisory

Information

Published : 2014-08-19 18:55

Updated : 2024-11-21 02:08


NVD link : CVE-2014-3490

Mitre link : CVE-2014-3490

CVE.ORG link : CVE-2014-3490


JSON object : View

Products Affected

redhat

  • jboss_enterprise_application_platform
  • resteasy