Lucene search

K
osvGoogleOSV:GHSA-G4JG-GPWV-P7WV
HistoryMay 17, 2022 - 1:50 a.m.

Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy

2022-05-1701:50:09
Google
osv.dev
16
resteasy
sensitive information
remote attackers
xml external entity (xxe) injection
cve-2012-0818
vulnerability
jaxb input

EPSS

0.004

Percentile

72.8%

The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.

EPSS

0.004

Percentile

72.8%