Total vulnerabilities in the database
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
Software | From | Fixed in |
---|---|---|
redhat / resteasy | 2.3.7 | 2.3.7.x |
redhat / resteasy | 3.0.9 | 3.0.9.x |
![]() |
- | 3.0.11.Final |