Back

HIGH

REJECTED CVE-2017-7492 SourceProvider in RestEasy-jaxrs is vulnerable to XXE

Published May 22, 2017

Description

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7503. Reason: This candidate is a reservation duplicate of CVE-2017-7503. Notes: All CVE users should reference CVE-2017-7503 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

Affected products

Remediation

Red Hat statement

After further analysis of this issue, it was determined that the flaw was in the XML Frameworks implementation on EAP 7, not in RESTEasy. If you use a javax.xml.transform.TransformerFactory to process a javax.xml.transform.Source instance please be aware of this outstanding issue with that functionality on EAP 7.0.x: https://bugzilla.redhat.com/show_bug.cgi?id=1451960

Metrics

Weaknesses (0)

No CWE recorded.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published May 22, 2017
Updated n/a
Reserved n/a
NVD
Status Rejected
Modified Nov 7, 2023
Red Hat
Severity Moderate
Public date May 8, 2017