Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6348

Опубликовано: 01 сент. 2016
Источник: redhat
CVSS3: 3.1
CVSS2: 2.6
EPSS Низкий

Описание

JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.

It was found that in some configurations the JacksonJsonpInterceptor is activated by default in RESTEasy. An attacker could use this flaw to launch a Cross Site Scripting Inclusion attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6Build and AssemblyWill not fix
Red Hat Enterprise Linux 7resteasy-baseFix deferred
Red Hat Enterprise Virtualization 3vdsm-jsonrpc-javaUnder investigation
Red Hat JBoss BRMS 5SecurityWill not fix
Red Hat JBoss BRMS 6Build and AssemblyWill not fix
Red Hat JBoss Data Grid 6BuildNot affected
Red Hat JBoss Data Grid 7resteasyAffected
Red Hat JBoss Data Virtualization 6ProductizationWill not fix
Red Hat JBoss Enterprise Application Platform 5jbossasWill not fix
Red Hat JBoss Enterprise Application Platform 6RESTEasyWill not fix

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1372129RESTEasy: Use of JacksonJsonpInterceptor in RESTEasy can lead to Cross Site Script Inclusion attack

EPSS

Процентиль: 33%
0.00132
Низкий

3.1 Low

CVSS3

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 9 лет назад

JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.

CVSS3: 6.1
nvd
почти 9 лет назад

JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.

CVSS3: 6.1
debian
почти 9 лет назад

JacksonJsonpInterceptor in RESTEasy might allow remote attackers to co ...

CVSS3: 6.1
github
больше 3 лет назад

JacksonJsonpInterceptor susceptible to cross-site script inclusion (XSSI) attack

EPSS

Процентиль: 33%
0.00132
Низкий

3.1 Low

CVSS3

2.6 Low

CVSS2