{"id":"GHSA-5m48-vr54-vmh3","summary":"jersey: XXE via parameter entities","details":"jersey: XXE via parameter entities not disabled by the jersey SAX parser","aliases":["CVE-2014-3643"],"modified":"2025-06-19T18:13:37.881595Z","published":"2022-05-17T19:57:08Z","database_specific":{"github_reviewed_at":"2025-06-19T17:08:27Z","nvd_published_at":"2019-12-15T22:15:00Z","cwe_ids":["CWE-611"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3643"},{"type":"WEB","url":"https://github.com/javaee/jersey-1.x/commit/49f1e5a6ac608ccb51939205e4739f328f2223e6"},{"type":"WEB","url":"https://access.redhat.com/security/cve/cve-2014-3643"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3643"},{"type":"PACKAGE","url":"https://github.com/javaee/jersey-1.x"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"WEB","url":"https://www.sourceclear.com/vulnerability-database/security/xml-external-entity-xxe/java/sid-22175"}],"affected":[{"package":{"name":"com.sun.jersey:jersey-core","ecosystem":"Maven","purl":"pkg:maven/com.sun.jersey/jersey-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.13"}]}],"versions":["0.9-ea","1.0","1.0.1","1.0.2","1.0.3","1.0.3.1","1.1.0-ea","1.1.1-ea","1.1.2-ea","1.1.3-ea","1.1.4","1.1.4.1","1.1.5","1.1.5-ea-20100104","1.1.5-ea-v20091019","1.1.5.1","1.1.5.2","1.10","1.10-b01","1.10-b02","1.10-b03","1.10-b04","1.10-b05","1.11","1.11-b01","1.11-b02","1.11-b03","1.11-b04","1.11.1","1.11.2","1.12","1.12-b01","1.13-b01","1.2","1.3","1.4","1.4-ea01","1.4-ea02","1.4-ea03","1.4-ea04","1.4-ea05","1.4-ea06","1.5","1.5-ea01","1.5-ea02","1.5-ea03","1.5-ea04","1.5-ea05","1.5-ea06","1.5-ea07","1.5-ea08","1.5-ea09","1.6","1.6-ea01","1.6-ea02","1.6-ea03","1.6-ea04","1.6-ea05","1.6-ea06","1.7","1.7-ea01","1.7-ea02","1.7-ea03","1.7-ea04","1.7-ea05","1.7-ea06","1.7-ea07","1.8","1.8-ea01","1.8-ea02","1.8-ea03","1.8-ea04","1.9","1.9-ea01","1.9-ea02","1.9-ea03","1.9-ea04","1.9-ea06","1.9-ea07","1.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5m48-vr54-vmh3/GHSA-5m48-vr54-vmh3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}