Skip to main content

Vendor/product archive

redhat / resteasy CVEs

Beta · best-effort

18 CVEs tagged to redhat / resteasy0 Critical, 6 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2021-20293

Published Jun 10, 2021

A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25724

Published May 26, 2021

A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25633

Published Sep 18, 2020

A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the serv…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1695

Published May 19, 2020

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9606

Published Mar 9, 2018

JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacke…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1051

Published Jan 25, 2018

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6347

Published Apr 20, 2017

Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6348

Published Apr 12, 2017

JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6346

Published Sep 7, 2016

RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6345

Published Sep 7, 2016

RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7839

Published Nov 25, 2014

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to con…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0818

Published Nov 23, 2012

RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity (XXE) injection attack.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5245

Published Nov 23, 2012

The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Arc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1