Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20289

Опубликовано: 26 мар. 2021
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:resteasy:*:*:*:*:*:*:*:*
Версия до 4.6.0 (включая)
Конфигурация 2
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*
Версия до 1.13.4 (исключая)
Конфигурация 4
cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.00086
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-209
CWE-209

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5.3
redhat
больше 4 лет назад

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5.3
debian
больше 4 лет назад

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.F ...

CVSS3: 5.3
github
больше 4 лет назад

Exposure of class information in RESTEasy

CVSS3: 5.3
fstec
больше 4 лет назад

Уязвимость программного средства RESTEasy, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 26%
0.00086
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-209
CWE-209