VDB
Sign up
MEDIUM6.5

GHSA-xrh2-c3rm-35jr

HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference

Quick fix

GHSA-xrh2-c3rm-35jr — org.hornetq.rest:hornetq-rest: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.5.0.Beta1</version> for org.hornetq.rest:hornetq-rest

Details

HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.hornetq.rest:hornetq-rest
Introduced in: 0Fixed in: 2.5.0.Beta1
Fix# pom.xml: bump <version>2.5.0.Beta1</version> for org.hornetq.rest:hornetq-rest

References