VulnerabilityModified
CVE-2020-25724
This flaw allows an attacker to gain access to privileged information.
MEDIUM 4.3EPSS 0.63%
Does this matter?
Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-567
- Affected
- redhat/resteasy · quarkus/quarkus
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1899354Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210702-0003/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1899354Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210702-0003/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.