Описание
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat BPM Suite 6 | resteasy-jaxrs | Out of support scope | ||
Red Hat CodeReady Studio 12 | resteasy-jaxrs | Fix deferred | ||
Red Hat Decision Manager 7 | resteasy-jaxrs | Not affected | ||
Red Hat Enterprise Linux 7 | resteasy-base | Out of support scope | ||
Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Fix deferred | ||
Red Hat Enterprise Linux 9 | resteasy | Affected | ||
Red Hat Fuse 7 | resteasy-core | Affected | ||
Red Hat Integration Camel K 1 | resteasy-core | Affected | ||
Red Hat JBoss BRMS 5 | resteasy-jaxrs | Out of support scope | ||
Red Hat JBoss BRMS 6 | resteasy-jaxrs | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.F ...
Уязвимость программного средства RESTEasy, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
5.3 Medium
CVSS3