CVE-2014-7839
Published:November 25, 2014
Updated:May 17, 2026
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
Affected Packages
org.jboss.resteasy:resteasy-jaxrs (JAVA):
Affected version(s) >=1.0-RC1 <3.0.11.FinalFix Suggestion:
Update to version 3.0.11.FinalRelated Resources (11)
Do you need more information?
Contact UsCVSS v3
Base Score:
6.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
LOW
CVSS v2
Base Score:
6.4
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
PARTIAL
Weakness Type (CWE)
EPSS
Base Score:
1.26