Back

MEDIUM

REST: XXE due to insecure configuration of RestEasy

Published Nov 12, 2019

Description

HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy

Affected products

Remediation

Red Hat statement

Not Vulnerable. HornetQ REST is not provided by any Red Hat product.

Red Hat mitigation

When using HornetQ REST in an application, add the following snippet to its web.xml file to disable entity expansion in RESTEasy as used by HornetQ REST endpoints: <context-param> <param-name>resteasy.document.expand.entity.references</param-name> <param-value>false</param-value> </context-param> Note that this <context-param> setting has precedence over <init-param>, and will override a contrary setting in an <init-param> element.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 12, 2019
Updated Aug 6, 2024
Reserved May 14, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 18, 2014
GHSA-XRH2-C3RM-35JR