Incorrect Privilege Assignment in RESTEasy
High severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
>= 2.3.1, <= 2.3.8.SP1
>= 3.0.0, <= 3.0.8.Final
Patched versions
2.3.8.SP2
3.0.9.Final
Description
Published by the National Vulnerability Database
Aug 19, 2014
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jul 7, 2022
Last updated
Jan 27, 2023
RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0818.
References