CVE-2014-7839

EPSS 1.3%

XML External Entity Reference in RESTEasy

發布日:2022/5/17修改日:2024/12/7

描述

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

受影響套件(1)

參考連結(9)