Moderate severityNVD Advisory· Published Nov 12, 2019· Updated Aug 6, 2024
CVE-2014-3599
CVE-2014-3599
Description
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.hornetq.rest:hornetq-restMaven | < 2.5.0.Beta1 | 2.5.0.Beta1 |
Affected products
2- HornetQ REST/HornetQ RESTv5Range: Fixed In Version: 2.5.0
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-xrh2-c3rm-35jrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-3599ghsaADVISORY
- access.redhat.com/security/cve/cve-2014-3599ghsax_refsource_MISCWEB
- bugzilla.redhat.com/show_bug.cgighsax_refsource_MISCWEB
- github.com/hornetq/hornetq/commit/b3a63576371828d5f8e64ba7ccbcecb1da8111d2ghsaWEB
- github.com/victims/victims-cve-db/blob/master/database/java/2014/3599.yamlghsaWEB
News mentions
0No linked articles in our index yet.