CVE-2012-0818
EPSS 1.4%Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
發布日:2022/5/17修改日:2024/12/3
描述
RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity (XXE) injection attack.
受影響套件(1)
- Maven/org.jboss.resteasy:resteasy-clientfrom 0, < 2.3.1
參考連結(29)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2012-0818
- PATCHhttps://github.com/resteasy/Resteasy
- WEBhttp://rhn.redhat.com/errata/RHSA-2012-0441.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2012-0519.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2012-1056.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2012-1057.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2012-1058.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2012-1059.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2012-1125.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2014-0371.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2014-0372.html
- WEBhttps://access.redhat.com/errata/RHSA-2012:0421
- WEBhttps://access.redhat.com/errata/RHSA-2012:0441
- WEBhttps://access.redhat.com/errata/RHSA-2012:0519
- WEBhttps://access.redhat.com/errata/RHSA-2012:1056
- WEBhttps://access.redhat.com/errata/RHSA-2012:1057
- WEBhttps://access.redhat.com/errata/RHSA-2012:1058
- WEBhttps://access.redhat.com/errata/RHSA-2012:1059
- WEBhttps://access.redhat.com/errata/RHSA-2012:1125
- WEBhttps://access.redhat.com/errata/RHSA-2013:1263
- WEBhttps://access.redhat.com/errata/RHSA-2014:0371
- WEBhttps://access.redhat.com/errata/RHSA-2014:0372
- WEBhttps://access.redhat.com/security/cve/CVE-2012-0818
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=785631
- WEBhttps://exchange.xforce.ibmcloud.com/vulnerabilities/72808
- WEBhttps://github.com/resteasy/resteasy/commit/71ace879cf92d323bfa4d3e88db0c3059109bbf6
- WEBhttps://issues.jboss.org/browse/RESTEASY-637
- WEBhttps://web.archive.org/web/20200229044434/http://www.securityfocus.com/bid/51748
- WEBhttps://web.archive.org/web/20200229045254/https://www.securityfocus.com/bid/51766