Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTI5cWotcnZ2Ni1xcm12

Cross-site scripting in RESTEasy

A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.

Permalink: https://github.com/advisories/GHSA-29qj-rvv6-qrmv
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTI5cWotcnZ2Ni1xcm12
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 3 years ago
Updated: over 1 year ago


CVSS Score: 5.4
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Identifiers: GHSA-29qj-rvv6-qrmv, CVE-2020-10688
References: Repository: https://github.com/quarkusio/quarkus
Blast Radius: 13.8

Affected Packages

maven:org.jboss.resteasy:resteasy-core
Dependent packages: 158
Dependent repositories: 357
Downloads:
Affected Version Ranges: >= 4.0.0, <= 4.5.2.Final, <= 3.11.0.Final
Fixed in: 4.5.3.Final, 3.11.1.Final
All affected versions:
All unaffected versions:
maven:org.jboss.resteasy:resteasy-bom
Dependent packages: 47
Dependent repositories: 326
Downloads:
Affected Version Ranges: >= 4.0.0, <= 4.5.2.Final, <= 3.11.0.Final
Fixed in: 4.5.3.Final, 3.11.1.Final
All affected versions:
All unaffected versions: