CVE-2014-7839
RESTeasy: External entities expanded by DocumentProvider
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
DocumentProvider en RESTEasy 2.3.7 y 3.0.9 no configura las caracteristicas (1) external-general-entities o (2) external-parameter-entities, lo que permite a atacantes remotos realizar ataques de entidad externa XML (XXE) a través de vectores no especificados.
It was found that the RESTEasy DocumentProvider did not set the external-parameter-entities and external-general-entities features appropriately, thus allowing external entity expansion. A remote attacker able to send XML requests to a RESTEasy endpoint could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XML eXternal Entity (XXE) attacks.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-10-03 CVE Reserved
- 2014-11-25 CVE Published
- 2024-07-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/62580 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2015-0675.html | 2015-04-23 | |
http://rhn.redhat.com/errata/RHSA-2015-0773.html | 2015-04-23 | |
http://rhn.redhat.com/errata/RHSA-2015-0850.html | 2015-04-23 | |
http://rhn.redhat.com/errata/RHSA-2015-0851.html | 2015-04-23 | |
https://issues.jboss.org/browse/RESTEASY-1130 | 2015-04-23 | |
https://access.redhat.com/security/cve/CVE-2014-7839 | 2015-05-14 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1165328 | 2015-05-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Resteasy Search vendor "Redhat" for product "Resteasy" | 2.3.7 Search vendor "Redhat" for product "Resteasy" and version "2.3.7" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Resteasy Search vendor "Redhat" for product "Resteasy" | 3.0.9 Search vendor "Redhat" for product "Resteasy" and version "3.0.9" | - |
Affected
|