Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1695

Опубликовано: 19 мая 2020
Источник: nvd
CVSS3: 7.5
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:resteasy:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.12.0 (исключая)
cpe:2.3:a:redhat:resteasy:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.6.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00224
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.

CVSS3: 7.5
redhat
около 5 лет назад

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.

CVSS3: 7.5
debian
около 5 лет назад

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final ...

rocky
около 4 лет назад

Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update

CVSS3: 7.5
github
около 3 лет назад

Improper Input Validation in RESTEasy

EPSS

Процентиль: 45%
0.00224
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
NVD-CWE-Other