Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2016-6347
Disclosure Date: April 20, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-6348
Disclosure Date: April 12, 2017 (last updated November 26, 2024)
JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.
0
Attacker Value
Unknown
CVE-2016-6346
Disclosure Date: September 07, 2016 (last updated November 25, 2024)
RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-6345
Disclosure Date: September 07, 2016 (last updated November 25, 2024)
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
0
Attacker Value
Unknown
CVE-2014-7839
Disclosure Date: November 25, 2014 (last updated October 05, 2023)
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-3490
Disclosure Date: August 19, 2014 (last updated October 05, 2023)
RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0818.
0
Attacker Value
Unknown
CVE-2012-0818
Disclosure Date: November 23, 2012 (last updated October 05, 2023)
RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity (XXE) injection attack.
0
Attacker Value
Unknown
CVE-2011-5245
Disclosure Date: November 23, 2012 (last updated October 05, 2023)
The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.
0