Oval Definition:oval:com.redhat.rhsa:def:20141011
Revision Date:2014-08-29Version:602
Title:RHSA-2014:1011: resteasy-base security update (Moderate)
Description:RESTEasy contains a JBoss project that provides frameworks to help build RESTful Web Services and RESTful Java applications. It is a fully certified and portable implementation of the JAX-RS specification.

  • It was found that the fix for CVE-2012-0818 was incomplete: external parameter entities were not disabled when the resteasy.document.expand.entity.references parameter was set to false. A remote attacker able to send XML requests to a RESTEasy endpoint could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks. (CVE-2014-3490)

    This issue was discovered by David Jorm of Red Hat Product Security.

    All resteasy-base users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-3490
    RHSA-2014:1011-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND Package Information
  • resteasy-base is earlier than 0:2.3.5-3.el7_0
  • AND resteasy-base is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-atom-provider is earlier than 0:2.3.5-3.el7_0
  • AND resteasy-base-atom-provider is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-jackson-provider is earlier than 0:2.3.5-3.el7_0
  • AND resteasy-base-jackson-provider is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-javadoc is earlier than 0:2.3.5-3.el7_0
  • AND resteasy-base-javadoc is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-jaxb-provider is earlier than 0:2.3.5-3.el7_0
  • AND resteasy-base-jaxb-provider is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-jaxrs is earlier than 0:2.3.5-3.el7_0
  • AND resteasy-base-jaxrs is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-jaxrs-all is earlier than 0:2.3.5-3.el7_0
  • AND resteasy-base-jaxrs-all is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-jaxrs-api is earlier than 0:2.3.5-3.el7_0
  • AND resteasy-base-jaxrs-api is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-jettison-provider is earlier than 0:2.3.5-3.el7_0
  • AND resteasy-base-jettison-provider is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-providers-pom is earlier than 0:2.3.5-3.el7_0
  • AND resteasy-base-providers-pom is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-tjws is earlier than 0:2.3.5-3.el7_0
  • AND resteasy-base-tjws is signed with Red Hat redhatrelease2 key
  • BACK