Skip to content

CVE-2014-3643 (High) detected in jersey-server-1.9.jar, jersey-core-1.9.jar #85

@mend-for-github-com

Description

@mend-for-github-com

CVE-2014-3643 - High Severity Vulnerability

Vulnerable Libraries - jersey-server-1.9.jar, jersey-core-1.9.jar

jersey-server-1.9.jar

Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services.

Library home page: https://jersey.java.net/

Path to dependency file: /ranger-hbase-plugin-shim/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/sun/jersey/jersey-server/1.9/jersey-server-1.9.jar

Dependency Hierarchy:

  • hbase-server-2.0.2.jar (Root Library)
    • hadoop-common-2.7.7.jar
      • jersey-server-1.9.jar (Vulnerable Library)
jersey-core-1.9.jar

Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services.

Library home page: https://jersey.java.net/

Path to dependency file: /ranger-hbase-plugin-shim/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/sun/jersey/jersey-core/1.9/jersey-core-1.9.jar

Dependency Hierarchy:

  • hbase-server-2.0.2.jar (Root Library)
    • hadoop-common-2.7.7.jar
      • jersey-core-1.9.jar (Vulnerable Library)

Found in HEAD commit: 3d8c1142c5739a45e8e562215c8c83915a44ee6c

Found in base branch: master

Vulnerability Details

jersey: XXE via parameter entities not disabled by the jersey SAX parser

Publish Date: 2019-12-15

URL: CVE-2014-3643

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3643

Release Date: 2019-12-15

Fix Resolution (com.sun.jersey:jersey-server): 1.13-b01

Direct dependency fix Resolution (org.apache.hbase:hbase-server): 2.0.3

Fix Resolution (com.sun.jersey:jersey-core): 1.12-b01

Direct dependency fix Resolution (org.apache.hbase:hbase-server): 2.0.3


⛑️ Automatic Remediation is available for this issue

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions