Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-89058

Опубликовано: 17 сент. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel 4 for Quarkus 3resteasy-coreAffected
Red Hat build of Apicurio Registry 3resteasy-coreFix deferred
Red Hat build of Debezium 3resteasy-coreAffected
Red Hat Build of Keycloakresteasy-coreAffected
Red Hat Build of Keycloakrhbk/keycloak-rhel9-operatorAffected
Red Hat build of Quarkusresteasy-coreAffected
Red Hat Certificate System 10redhat-pki:10/redhat-pkiAffected
Red Hat Certificate System 11redhat-pkiAffected
Red Hat Enterprise Linux 10dogtag-pkiAffected
Red Hat Enterprise Linux 8pki-core:10.6/pki-coreAffected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2519775resteasy-core: RESTEasy: CorsFilter Reflects Arbitrary Origin with Credentials under Wildcard Config

EPSS

Процентиль: 36%
0.00424
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 дня назад

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality.

CVSS3: 7.4
nvd
5 дней назад

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality.

CVSS3: 7.4
debian
5 дней назад

A flaw was found in RESTEasy's CorsFilter, which, when configured to a ...

EPSS

Процентиль: 36%
0.00424
Низкий

7.4 High

CVSS3