DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
{ "nvd_published_at": "2014-11-25T15:59:00Z", "cwe_ids": [ "CWE-20", "CWE-611" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-06-17T01:12:47Z" }