org.jboss.resteasy:resteasy-bom
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jboss.resteasy:resteasy-bompage 1 of 1
- CVE-2016-9606HIGHCVSS 8.1✓ Fixed in 3.1.2.Final2018-03-09
vulnerable: 1.2.1.GA ... 3.1.1.Final (68 versions)
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permis…
- CVE-2020-10688MEDIUMCVSS 6.1EG 6.1✓ Fixed in 4.5.3.Final2021-05-27
vulnerable: 4.0.0.Final ... 4.5.2.Final (14 versions)
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to laun…
- CVE-2020-14326HIGHCVSS 7.5EG 7.5✓ Fixed in 4.5.6.Final2021-06-02
vulnerable: 1.2.1.GA ... 4.5.5.Final (145 versions)
A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with higher CPU time spent searching and adding the entry. This flaw allows an attacker to cau…
- CVE-2020-25724MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.0-beta-22021-05-26
vulnerable: 1.2.1.GA, 1.2.GA, 2.0-beta-1
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity…
- CVE-2021-20293MEDIUMCVSS 6.1EG 6.12021-06-10
vulnerable: 1.2.1.GA ... 4.6.0.Final (155 versions)
A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.ws.rs.PathParam without any @Produces MediaType. This flaw a…
Check whether org.jboss.resteasy:resteasy-bom is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jboss.resteasy:resteasy-bom CVEs against the assets you own.
Start Free Scan →