SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-25724

This flaw allows an attacker to gain access to privileged information.

MEDIUM 4.3EPSS 0.63%

Does this matter?

Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.63% probability · 48th percentile
CISA KEV
Not listed
Weakness
CWE-567
Affected
redhat/resteasy · quarkus/quarkus
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.