Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-12799

Опубликовано: 07 июл. 2026
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.

Отчет

This Moderate impact Cross-Site Scripting (XSS) flaw in Jastow, as used in Red Hat Enterprise Application Platform, arises when a server is configured to allow unescaped characters in URLs with embedded Undertow. Exploitation requires a specific, non-default configuration, limiting its applicability in typical deployments.

Меры по смягчению последствий

It is possible to contruct successful attack vector if and only if customer or client is using embedded Undertow and Jastow together in their application and the following conditions are met:

  • Undertow was configured with UndertowOptions.ALLOW_UNESCAPED_CHARACTERS_IN_URL set to 'true' value
  • DeploymentInfo configured with setEscapeErrorMessage(true) method was passed to Undertow's Servlet Container instance

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 7eap74-els-openjdk11-openshift-rhel8/eap74-els-openjdk11-openshift-rhel8Fix deferred
Red Hat JBoss Enterprise Application Platform 7eap74-els-openjdk17-openshift-rhel8/eap74-els-openjdk17-openshift-rhel8Fix deferred
Red Hat JBoss Enterprise Application Platform 7eap74-els-openjdk8-openshift-rhel8/eap74-els-openjdk8-openshift-rhel8Fix deferred
Red Hat JBoss Enterprise Application Platform 7io.undertow.jastow-jastowAffected
Red Hat JBoss Enterprise Application Platform 7jastowFix deferred
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk17-openshift-rhel8Fix deferred
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk8-openshift-rhel8Fix deferred
Red Hat JBoss Enterprise Application Platform 8jastowFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packio.undertow.jastow-jastowNot affected
Red Hat JBoss Enterprise Application Platform Expansion PackjastowFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2413071jastow: Jastow Cross-Site Scripting attack due to unsanitized URI

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 месяцев назад

A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.

CVSS3: 6.5
github
около 2 месяцев назад

A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.

6.5 Medium

CVSS3