Bug 1105242 (CVE-2014-3481) - CVE-2014-3481 JBoss AS JAX-RS: Information disclosure via XML eXternal Entity (XXE)
Summary: CVE-2014-3481 JBoss AS JAX-RS: Information disclosure via XML eXternal Entity...
Status: CLOSED ERRATA
Alias: CVE-2014-3481
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20140605,repor...
Keywords: Security
Depends On: 1160697 1105142 1105250 1124642 1124643 1124644 1124645 1124646 1124647 1124648 1124649 1124650 1124651 1166434
Blocks: 1105426 1108493 1124639 1139455 1182400 1182419 1200191
TreeView+ depends on / blocked
 
Reported: 2014-06-05 16:29 UTC by Arun Babu Neelicattu
Modified: 2019-06-11 11:13 UTC (History)
42 users (show)

(edit)
It was found that the default context parameters as provided to RESTEasy deployments by JBoss EAP did not explicitly disable external entity expansion for RESTEasy. A remote attacker could use this flaw to perform XML External Entity (XXE) attacks on RESTEasy applications accepting XML input.
Clone Of:
(edit)
Last Closed: 2019-06-08 02:33:19 UTC


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:0797 normal SHIPPED_LIVE Moderate: Red Hat JBoss Enterprise Application Platform 6.2.4 update 2014-06-26 19:00:47 UTC
Red Hat Knowledge Base (Solution) 1146253 None None None Never
Red Hat Product Errata RHSA-2014:0798 normal SHIPPED_LIVE Moderate: Red Hat JBoss Enterprise Application Platform 6.2.4 update 2014-06-26 19:16:02 UTC
Red Hat Product Errata RHSA-2014:0799 normal SHIPPED_LIVE Moderate: Red Hat JBoss Enterprise Application Platform 6.2.4 update 2014-06-26 19:11:00 UTC
Red Hat Product Errata RHSA-2014:1904 normal SHIPPED_LIVE Important: Red Hat JBoss Operations Network 3.3.0 update 2014-11-25 21:48:32 UTC
Red Hat Product Errata RHSA-2015:0675 normal SHIPPED_LIVE Important: Red Hat JBoss Data Virtualization 6.1.0 update 2015-03-11 20:51:21 UTC
Red Hat Product Errata RHSA-2015:0720 normal SHIPPED_LIVE Important: Red Hat JBoss Fuse Service Works 6.0.0 security update 2015-03-25 01:05:53 UTC
Red Hat Product Errata RHSA-2015:0765 normal SHIPPED_LIVE Important: Red Hat JBoss Data Virtualization 6.0.0 security update 2015-03-31 21:00:43 UTC
Red Hat Product Errata RHSA-2015:1009 normal SHIPPED_LIVE Important: Red Hat JBoss Portal 6.2.0 update 2015-05-14 19:14:47 UTC

Description Arun Babu Neelicattu 2014-06-05 16:29:22 UTC
IssueDescription:

It was found that the default context parameters as provided to RESTEasy deployments by JBoss EAP did not explicitly disable external entity expansion for RESTEasy. A remote attacker could use this flaw to perform XML External Entity (XXE) attacks on RESTEasy applications accepting XML input.

Comment 3 Martin Prpič 2014-06-19 09:27:53 UTC
Acknowledgements:

This issue was discovered by the Red Hat JBoss Enterprise Application Platform QE team.

Comment 4 errata-xmlrpc 2014-06-26 15:02:00 UTC
This issue has been addressed in following products:

  Red Hat JBoss Enterprise Application Platform 6.2.4

Via RHSA-2014:0797 https://rhn.redhat.com/errata/RHSA-2014-0797.html

Comment 5 errata-xmlrpc 2014-06-26 15:18:43 UTC
This issue has been addressed in following products:

  JBEAP 6.2 for RHEL 5

Via RHSA-2014:0798 https://rhn.redhat.com/errata/RHSA-2014-0798.html

Comment 6 errata-xmlrpc 2014-06-26 16:18:29 UTC
This issue has been addressed in following products:

  JBEAP 6.2 for RHEL 6

Via RHSA-2014:0799 https://rhn.redhat.com/errata/RHSA-2014-0799.html

Comment 8 Arun Babu Neelicattu 2014-07-30 03:10:39 UTC
Created wildfly tracking bugs for this issue:

Affects: fedora-all [bug 1124642]

Comment 9 Arun Babu Neelicattu 2014-07-30 06:53:52 UTC
Upstream Issue:

https://issues.jboss.org/browse/WFLY-3458

Comment 10 Chess Hazlett 2014-09-19 02:14:52 UTC
This issue has been addressed in following products:

  JBoss Data Grid 6.3.0

Via RHSA-2014:0895 https://rhn.redhat.com/errata/RHSA-2014-0895.html

Comment 14 errata-xmlrpc 2014-11-25 16:48:54 UTC
This issue has been addressed in the following products:

  JBoss Operations Network 3.3.0

Via RHSA-2014:1904 https://rhn.redhat.com/errata/RHSA-2014-1904.html

Comment 16 errata-xmlrpc 2015-03-11 16:53:21 UTC
This issue has been addressed in the following products:

JBoss Data Virtualization 6.1.0

Via RHSA-2015:0675 https://rhn.redhat.com/errata/RHSA-2015-0675.html

Comment 17 errata-xmlrpc 2015-03-24 21:06:51 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Fuse Service Works 6.0.0

Via RHSA-2015:0720 https://rhn.redhat.com/errata/RHSA-2015-0720.html

Comment 18 errata-xmlrpc 2015-03-31 17:01:46 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Data Virtualization 6.0.0

Via RHSA-2015:0765 https://rhn.redhat.com/errata/RHSA-2015-0765.html

Comment 19 errata-xmlrpc 2015-05-14 15:20:54 UTC
This issue has been addressed in the following products:

  JBoss Portal 6.2.0

Via RHSA-2015:1009 https://rhn.redhat.com/errata/RHSA-2015-1009.html


Note You need to log in before you can comment on or make changes to this bug.