Описание
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel 4 for Quarkus 3 | resteasy-core | Affected | ||
| Red Hat build of Apicurio Registry 3 | resteasy-core | Fix deferred | ||
| Red Hat build of Debezium 3 | resteasy-core | Affected | ||
| Red Hat Build of Keycloak | resteasy-core | Affected | ||
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9-operator | Affected | ||
| Red Hat build of Quarkus | resteasy-core | Affected | ||
| Red Hat Certificate System 10 | redhat-pki:10/redhat-pki | Affected | ||
| Red Hat Certificate System 11 | redhat-pki | Affected | ||
| Red Hat Enterprise Linux 10 | dogtag-pki | Affected | ||
| Red Hat Enterprise Linux 8 | pki-core:10.6/pki-core | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.4 High
CVSS3
Связанные уязвимости
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality.
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality.
A flaw was found in RESTEasy's CorsFilter, which, when configured to a ...
EPSS
7.4 High
CVSS3