Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-244r-fcj3-ghjq

Опубликовано: 07 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Exposure of class information in RESTEasy

A flaw was found in RESTEasy in all current versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.

Пакеты

Наименование

org.jboss.resteasy:resteasy-core

maven
Затронутые версииВерсия исправления

>= 4.6.0, < 4.6.1

4.6.1

Наименование

org.jboss.resteasy:resteasy-core

maven
Затронутые версииВерсия исправления

>= 4.0.0, < 4.5.10

4.5.10

Наименование

org.jboss.resteasy:resteasy-core

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.16.0

3.16.0

EPSS

Процентиль: 25%
0.00084
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-209
CWE-668

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5.3
redhat
больше 4 лет назад

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5.3
nvd
больше 4 лет назад

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5.3
debian
больше 4 лет назад

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.F ...

CVSS3: 5.3
fstec
больше 4 лет назад

Уязвимость программного средства RESTEasy, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 25%
0.00084
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-209
CWE-668