jersey: XXE via parameter entities not disabled by the jersey SAX parser
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3643 | Issue Tracking Third Party Advisory |
https://access.redhat.com/security/cve/cve-2014-3643 | Third Party Advisory |
https://www.oracle.com/security-alerts/cpujul2022.html |
Configurations
Information
Published : 2019-12-15 14:15
Updated : 2022-07-25 11:15
NVD link : CVE-2014-3643
Mitre link : CVE-2014-3643
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
jersey_project
- jersey