GHSA-rj4p-7mm6-gm9j
Dashboard / Vulnerabilities / GHSA-rj4p-7mm6-gm9j
Summary: JBossWS vulnerable to uncontrolled recursion
Details: DOMUtils.java in org.jboss.ws:jbossws-common does not properly handle recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted request containing an XML document with a DOCTYPE declaration and a large number of nested entity references, a similar issue to CVE-2003-1564.
References: https://nvd.nist.gov/vuln/detail/CVE-2011-1483, https://bugzilla.redhat.com/show_bug.cgi?id=692584, https://github.com/jbossws/jbossws-common, http://source.jboss.org/changelog/JBossWS/?cs=13996
Affected packages
Package
Name: org.jboss.ws:jbossws-common
Purl: pkg:maven/org.jboss.ws/jbossws-common
Affected ranges
Type: ECOSYSTEM
Events:
