MGASA-2014-0547
Dashboard / Vulnerabilities / MGASA-2014-0547
Summary: Updated resteasy package fix CVE-2014-3490
Details: Updated resteasy packages fixes security vulnerability: It was found that the fix for CVE-2012-0818 was incomplete: external parameter entities were not disabled when the resteasy.document.expand.entity.references parameter was set to false. A remote attacker able to send XML requests to a RESTEasy endpoint could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks (CVE-2014-3490).
References: https://advisories.mageia.org/MGASA-2014-0547.html, https://bugs.mageia.org/show_bug.cgi?id=13870, https://rhn.redhat.com/errata/RHSA-2014-1011.html
Affected packages
Package
Name: resteasy
Purl: pkg:rpm/mageia/resteasy?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
