Описание
Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
It was found that the default exception handler in RESTEasy did not properly validate user input. An attacker could use this flaw to launch a relected XSS attack.
Отчет
This issue affects the versions of RESTEasy as shipped with Red Hat Satellite 6. Red Hat Product Security has rated this issue as having a security impact of Moderate. Additionally Red Hat Satellite does not use the default ExceptionMapper, and the custom exception handler does not allow return type of text/html. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | Build and Assembly | Not affected | ||
| Red Hat Enterprise Linux 7 | resteasy-base | Will not fix | ||
| Red Hat Enterprise Virtualization 3 | vdsm-jsonrpc-java | Under investigation | ||
| Red Hat JBoss BRMS 5 | Security | Will not fix | ||
| Red Hat JBoss BRMS 6 | Build and Assembly | Not affected | ||
| Red Hat JBoss Data Grid 6 | Build | Not affected | ||
| Red Hat JBoss Data Grid 7 | resteasy | Affected | ||
| Red Hat JBoss Data Virtualization 6 | Productization | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 5 | jbossas | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 6 | RESTEasy | Not affected |
Показывать по
Дополнительная информация
Статус:
5.4 Medium
CVSS3
4.3 Medium
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Cross-site scripting (XSS) vulnerability in the default exception hand ...
Improper Neutralization of Input During Web Page Generation in RESTEasy
5.4 Medium
CVSS3
4.3 Medium
CVSS2