SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-20289

The highest threat from this vulnerability is to data confidentiality.

MEDIUM 5.3EPSS 1.40%

Does this matter?

Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.40% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-209
Affected
redhat/resteasy · netapp/oncommand insight · quarkus/quarkus · oracle/communications cloud native core console
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.