Описание
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
A flaw was found in Resteasy, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat BPM Suite 6 | resteasy-jaxrs | Out of support scope | ||
Red Hat BPM Suite 6 | resteasy-jaxrs-all | Out of support scope | ||
Red Hat Decision Manager 7 | resteasy-jaxrs | Not affected | ||
Red Hat Enterprise Linux 7 | resteasy-base | Will not fix | ||
Red Hat JBoss BRMS 5 | resteasy-jaxrs | Out of support scope | ||
Red Hat JBoss Data Virtualization 6 | resteasy-jaxrs | Out of support scope | ||
Red Hat JBoss Data Virtualization 6 | resteasy-jaxrs-all | Out of support scope | ||
Red Hat JBoss Enterprise Application Platform 5 | resteasy-jaxrs | Out of support scope | ||
Red Hat JBoss Enterprise Application Platform 6 | resteasy-jaxrs | Out of support scope | ||
Red Hat JBoss Fuse 6 | resteasy-jaxrs | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final ...
Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update
EPSS
7.5 High
CVSS3