Описание
A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.ws.rs.PathParam without any @Produces MediaType. This flaw allows an attacker to launch a reflected XSS attack. The highest threat from this vulnerability is to data confidentiality and integrity.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Quarkus | resteasy | Will not fix | ||
| Red Hat Enterprise Linux 7 | resteasy-base | Will not fix | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Will not fix | ||
| Red Hat Fuse 7 | resteasy | Will not fix | ||
| Red Hat Integration Camel K 1 | resteasy-core | Will not fix | ||
| Red Hat Integration Camel Quarkus 1 | resteasy-core | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 6 | resteasy | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | resteasy | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | resteasy | Will not fix | ||
| Red Hat OpenShift Application Runtimes | resteasy | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.ws.rs.PathParam without any @Produces MediaType. This flaw allows an attacker to launch a reflected XSS attack. The highest threat from this vulnerability is to data confidentiality and integrity.
A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.ws.rs.PathParam without any @Produces MediaType. This flaw allows an attacker to launch a reflected XSS attack. The highest threat from this vulnerability is to data confidentiality and integrity.
A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in a ...
EPSS
5.4 Medium
CVSS3