{"id":"CVE-2011-1483","aliases":[],"url":"https://o3.security/vulnerability/CVE-2011-1483","summary":"JBossWS vulnerable to uncontrolled recursion","details":"DOMUtils.java in org.jboss.ws:jbossws-common does not properly handle recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted request containing an XML document with a DOCTYPE declaration and a large number of nested entity references, a similar issue to CVE-2003-1564.","published":"2022-05-13T01:39:29Z","modified":"2023-11-08T03:56:59.214188Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jboss.ws:jbossws-common","fixedVersion":"2.1.0.Final"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1483"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=692584"},{"type":"PACKAGE","url":"https://github.com/jbossws/jbossws-common"},{"type":"WEB","url":"http://source.jboss.org/changelog/JBossWS/?cs=13996"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:56:59.214188Z"}}