VulnerabilityModified
CVE-2020-10688
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs.
MEDIUM 6.1EPSS 1.39%
Does this matter?
Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.
Description
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- redhat/fuse · redhat/jboss enterprise application platform · redhat/openshift application runtimes · redhat/resteasy
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1814974Issue Tracking, Patch, Vendor Advisory
- https://github.com/quarkusio/quarkus/issues/7248Exploit, Issue Tracking, Third Party Advisory
- https://issues.redhat.com/browse/RESTEASY-2519Issue Tracking, Permissions Required, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210706-0008/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1814974Issue Tracking, Patch, Vendor Advisory
- https://github.com/quarkusio/quarkus/issues/7248Exploit, Issue Tracking, Third Party Advisory
- https://issues.redhat.com/browse/RESTEASY-2519Issue Tracking, Permissions Required, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210706-0008/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.