HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Package
Affected versions
< 2.5.0.Beta1
Patched versions
2.5.0.Beta1
Description
Published by the National Vulnerability Database
Nov 12, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Nov 22, 2022
Last updated
Feb 2, 2023
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy.
References