PT-2014-5375 · Jboss · Picketlink
CVE-2014-3530
·
Publicado
2014-07-22
·
Atualizado
2023-02-13
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PicketLink versions 5.2.0 through 6.2.4
Description
The issue is related to an XML External Entity (XXE) problem, where the
org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink expands entity references. This allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified vectors.Recommendations
For versions 5.2.0 through 6.2.4, consider disabling the
org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method as a temporary workaround until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation.Correção
XXE
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Picketlink