CVE-2012-0818: XEE
Published Dec 30, 2011
·Updated
RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity (XXE) injection attack.
Affected Software
26 affected componentsFixes available
redhat/resteasy<0:1.2.1-10.CP02_patch01.1.ep5.el5
0:1.2.1-10.CP02_patch01.1.ep5.el5
redhat/resteasy<0:1.2.1-10.CP02_patch01.1.ep5.el6
0:1.2.1-10.CP02_patch01.1.ep5.el6
redhat/resteasy<0:1.2.1-10.CP02_patch01.1.ep5.el4
0:1.2.1-10.CP02_patch01.1.ep5.el4
redhat/otopi<0:1.1.0-1.el6e
0:1.1.0-1.el6e
redhat/ovirt-host-deploy<0:1.1.0-1.el6e
0:1.1.0-1.el6e
redhat/python-daemon<0:1.5.2-1.el6
0:1.5.2-1.el6
redhat/python-kitchen<0:1.1.1-2.el6e
0:1.1.1-2.el6e
redhat/python-lockfile<0:0.8-5.el6
0:0.8-5.el6
redhat/python-ply<0:3.3-7.el6e
0:3.3-7.el6e
redhat/redhat-access-plugin-storage<0:2.1.0-0.el6
0:2.1.0-0.el6
redhat/rhsc-cli<0:2.1.0.0-0.bb3a.el6
0:2.1.0.0-0.bb3a.el6
redhat/rhsc-log-collector<0:2.1-0.1.el6
0:2.1-0.1.el6
redhat/rhsc-sdk<0:2.1.0.0-0.bb3a.el6
0:2.1.0.0-0.bb3a.el6
redhat resteasy<=2.3.0
redhat resteasy=1.0.0
redhat resteasy=1.0.1
redhat resteasy=1.0.2
redhat resteasy=1.1
redhat resteasy=1.2
redhat resteasy=2.0.0
redhat resteasy=2.0.1
redhat resteasy=2.1.0
redhat resteasy=2.2.0
redhat resteasy=2.2.1
redhat resteasy=2.2.2
redhat resteasy=2.2.3
Remediation
Patch Available
Event History
Dec 30, 2011
CVE Published
12:00 AM
Nov 23, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is the severity of CVE-2012-0818?
CVE-2012-0818 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2012-0818?
To fix CVE-2012-0818, upgrade REDHAT RESTEasy to version 2.3.1 or later.
3
What is the impact of CVE-2012-0818?
The impact of CVE-2012-0818 allows remote attackers to read arbitrary files via an XML external entity injection.
4
Which versions of RESTEasy are affected by CVE-2012-0818?
Versions of RESTEasy before 2.3.1 are affected by CVE-2012-0818.
5
Is CVE-2012-0818 an XML external entity attack?
Yes, CVE-2012-0818 is specifically an XML external entity (XXE) injection attack.