MEDIUM6.5
GHSA-xrh2-c3rm-35jr
HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference
Quick fix
GHSA-xrh2-c3rm-35jr — org.hornetq.rest:hornetq-rest: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.5.0.Beta1</version> for org.hornetq.rest:hornetq-restDetails
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.hornetq.rest:hornetq-rest
Introduced in:
0Fixed in: 2.5.0.Beta1Fix
# pom.xml: bump <version>2.5.0.Beta1</version> for org.hornetq.rest:hornetq-restReferences
- https://nvd.nist.gov/vuln/detail/CVE-2014-3599[ADVISORY]
- https://github.com/hornetq/hornetq/commit/b3a63576371828d5f8e64ba7ccbcecb1da8111d2[WEB]
- https://access.redhat.com/security/cve/cve-2014-3599[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3599[WEB]
- https://github.com/hornetq/hornetq[PACKAGE]
- https://github.com/victims/victims-cve-db/blob/master/database/java/2014/3599.yaml[WEB]