{"id":"MGASA-2014-0547","summary":"Updated resteasy package fix CVE-2014-3490","details":"Updated resteasy packages fixes security vulnerability:\n\nIt was found that the fix for CVE-2012-0818 was incomplete: external\nparameter entities were not disabled when the\nresteasy.document.expand.entity.references parameter was set to false.\nA remote attacker able to send XML requests to a RESTEasy endpoint could\nuse this flaw to read files accessible to the user running the application\nserver, and potentially perform other more advanced XXE attacks\n(CVE-2014-3490).\n","modified":"2026-04-16T06:24:03.455726364Z","published":"2014-12-26T17:04:58Z","upstream":["CVE-2014-3490"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0547.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=13870"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2014-1011.html"}],"affected":[{"package":{"name":"resteasy","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/resteasy?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.1-3.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0547.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}