GHSA-5m48-vr54-vmh3

Suggest an improvement
Source
https://github.com/advisories/GHSA-5m48-vr54-vmh3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5m48-vr54-vmh3/GHSA-5m48-vr54-vmh3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5m48-vr54-vmh3
Aliases
  • CVE-2014-3643
Downstream
Published
2022-05-17T19:57:08Z
Modified
2025-06-19T18:13:37.881595Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
jersey: XXE via parameter entities
Details

jersey: XXE via parameter entities not disabled by the jersey SAX parser

Database specific
{
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-611"
    ],
    "nvd_published_at": "2019-12-15T22:15:00Z",
    "severity": "HIGH",
    "github_reviewed_at": "2025-06-19T17:08:27Z"
}
References

Affected packages

Maven / com.sun.jersey:jersey-core

Package

Name
com.sun.jersey:jersey-core
View open source insights on deps.dev
Purl
pkg:maven/com.sun.jersey/jersey-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.13

Affected versions

0.*
0.9-ea
1.*
1.0
1.0.1
1.0.2
1.0.3
1.0.3.1
1.1.0-ea
1.1.1-ea
1.1.2-ea
1.1.3-ea
1.1.4
1.1.4.1
1.1.5
1.1.5-ea-v20091019
1.1.5-ea-20100104
1.1.5.1
1.1.5.2
1.2
1.3
1.4
1.4-ea01
1.4-ea02
1.4-ea03
1.4-ea04
1.4-ea05
1.4-ea06
1.5
1.5-ea01
1.5-ea02
1.5-ea03
1.5-ea04
1.5-ea05
1.5-ea06
1.5-ea07
1.5-ea08
1.5-ea09
1.6
1.6-ea01
1.6-ea02
1.6-ea03
1.6-ea04
1.6-ea05
1.6-ea06
1.7
1.7-ea01
1.7-ea02
1.7-ea03
1.7-ea04
1.7-ea05
1.7-ea06
1.7-ea07
1.8
1.8-ea01
1.8-ea02
1.8-ea03
1.8-ea04
1.9
1.9-ea01
1.9-ea02
1.9-ea03
1.9-ea04
1.9-ea06
1.9-ea07
1.9.1
1.10-b01
1.10-b02
1.10-b03
1.10-b04
1.10-b05
1.10
1.11-b01
1.11-b02
1.11-b03
1.11-b04
1.11
1.11.1
1.11.2
1.12-b01
1.12
1.13-b01

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5m48-vr54-vmh3/GHSA-5m48-vr54-vmh3.json"