Show plain JSON{"acknowledgement": "This issue was discovered by Katerina Novotna (Red Hat).", "bugzilla": {"description": "REJECTED CVE-2017-7492 SourceProvider in RestEasy-jaxrs is vulnerable to XXE", "id": "1448753", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1448753"}, "csaw": false, "cvss3": {"cvss3_base_score": "7.5", "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:H", "status": "draft"}, "details": ["No description is available for this CVE."], "name": "CVE-2017-7492", "package_state": [{"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6", "fix_state": "Not affected", "package_name": "REST", "product_name": "Red Hat JBoss Enterprise Application Platform 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7", "fix_state": "Affected", "package_name": "REST", "product_name": "Red Hat JBoss Enterprise Application Platform 7"}], "public_date": "2017-05-08T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2017-7492\nhttps://nvd.nist.gov/vuln/detail/CVE-2017-7492"], "statement": "After further analysis of this issue, it was determined that the flaw was in the XML Frameworks implementation on EAP 7, not in RESTEasy.\nIf you use a javax.xml.transform.TransformerFactory to process a javax.xml.transform.Source instance please be aware of this outstanding issue with that functionality on EAP 7.0.x:\nhttps://bugzilla.redhat.com/show_bug.cgi?id=1451960", "threat_severity": "Moderate"}