Red Hat addressed CVE-2014-3490, a moderate-severity XML external entity (XXE) vulnerability in RESTEasy caused by an incomplete correction for CVE-2012-0818. Even when resteasy.document.expand.entity.references was set to false, RESTEasy continued to permit external parameter entities. An unauthenticated remote attacker able to submit XML to a vulnerable RESTEasy endpoint could read files accessible to the application-server account, make server-side HTTP requests that bypass network restrictions, or consume resources for denial of service.
Fixes were released for affected RESTEasy packages in Red Hat Enterprise Linux and multiple JBoss products, with upstream patches merged into RESTEasy 2.3 and master branches. Red Hat also included the remediation in the Important-rated RHSA-2015:0720 rollup for JBoss Fuse Service Works 6.0.0; organizations should apply the applicable vendor updates and ensure XML parsers and validators disable external entity expansion, including DTD external parameter entities.

See affected versions and whether adversaries are exploiting it.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important-rated RHSA-2015:0720 and rollup patch 4 for JBoss Fuse Service Works 6.0.0. The cumulative update fixed CVE-2014-3490 along with 17 other security vulnerabilities across bundled components.
Red Hat released Moderate-rated RHSA-2015:0217 for JBoss EAP 6.3.3 on RHEL 6, replacing EAP 6.3.2. The update fixed CVE-2014-7839, an RESTEasy DocumentProvider XXE issue that could allow remote file disclosure, along with four other EAP vulnerabilities.
Red Hat released RHSA-2014:1011 for the resteasy-base component in Red Hat Enterprise Linux 7, remediating CVE-2014-3490, an XXE flaw allowing external parameter entities despite a disabled entity-reference setting.
Fedora 20's stable repository received resteasy-3.0.6-3.fc20, a package fixing the CVE-2014-3490 RESTEasy XXE vulnerability.
RHSA-2015:0765 remediated CVE-2014-3490 in the RESTEasy component included with JBoss Data Virtualization 6.0.
RHSA-2015:0675 fixed CVE-2014-3490 in the RESTEasy component shipped with JBoss Data Virtualization 6.1.
Red Hat issued RHSA-2015:0234 for JBoss BPMS 6.0 and RHSA-2015:0235 for JBoss BRMS 6.0 to address CVE-2014-3490 in RESTEasy.
RESTEasy merged pull request #611 (commit 7a0b80f) into its Branch_2_3 branch for RESTEASY-1130, adding configuration for expansion of external general and parameter entities and tests including one for Red Hat Xerces.
RHSA-2014:1298 remediated CVE-2014-3490 in JBoss Data Grid 6.3, which bundled the affected RESTEasy component.
Red Hat issued RHSA-2014:1039 and RHSA-2014:1040 to fix the RESTEasy XXE vulnerability in JBoss Enterprise Application Platform 6.3, including builds for RHEL 5, RHEL 6, and RHEL 7.
Upstream RESTEasy applied pull requests 533 for the 2.3 branch and 521 for the master branch, including commit 9b7d0f574cafdcf3bea5428f3145ab4908fc6d83, to address CVE-2014-3490; RESTEASY-1073 was closed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourcegithub.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.