GHSA-wrrh-g7h3-gqmx
Dashboard / Vulnerabilities / GHSA-wrrh-g7h3-gqmx
Summary: Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
Details: RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity (XXE) injection attack.
References: https://nvd.nist.gov/vuln/detail/CVE-2012-0818, https://github.com/resteasy/resteasy/commit/71ace879cf92d323bfa4d3e88db0c3059109bbf6, https://web.archive.org/web/20200229045254/https://www.securityfocus.com/bid/51766, https://web.archive.org/web/20200229044434/http://www.securityfocus.com/bid/51748, https://issues.jboss.org/browse/RESTEASY-637, https://github.com/resteasy/Resteasy, https://exchange.xforce.ibmcloud.com/vulnerabilities/72808, https://bugzilla.redhat.com/show_bug.cgi?id=785631, https://access.redhat.com/security/cve/CVE-2012-0818, https://access.redhat.com/errata/RHSA-2014:0372, https://access.redhat.com/errata/RHSA-2014:0371, https://access.redhat.com/errata/RHSA-2013:1263, https://access.redhat.com/errata/RHSA-2012:1125, https://access.redhat.com/errata/RHSA-2012:1059, https://access.redhat.com/errata/RHSA-2012:1058, https://access.redhat.com/errata/RHSA-2012:1057, https://access.redhat.com/errata/RHSA-2012:1056, https://access.redhat.com/errata/RHSA-2012:0519, https://access.redhat.com/errata/RHSA-2012:0441, https://access.redhat.com/errata/RHSA-2012:0421, http://rhn.redhat.com/errata/RHSA-2012-0441.html, http://rhn.redhat.com/errata/RHSA-2012-0519.html, http://rhn.redhat.com/errata/RHSA-2012-1056.html, http://rhn.redhat.com/errata/RHSA-2012-1057.html, http://rhn.redhat.com/errata/RHSA-2012-1058.html, http://rhn.redhat.com/errata/RHSA-2012-1059.html, http://rhn.redhat.com/errata/RHSA-2012-1125.html, http://rhn.redhat.com/errata/RHSA-2014-0371.html, http://rhn.redhat.com/errata/RHSA-2014-0372.html
Affected packages
Package
Name: org.jboss.resteasy:resteasy-client
Purl: pkg:maven/org.jboss.resteasy/resteasy-client
Affected ranges
Type: ECOSYSTEM
Events:
