Search CVE reports
11 – 18 of 18 results
CVE-2018-1051
Low priorityIt was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.
2 affected packages
resteasy, resteasy3.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
resteasy | Not affected | Not affected | Not affected | Not in release | Vulnerable |
resteasy3.0 | Not affected | Not affected | Not affected | Not affected | Not in release |
CVE-2017-7561
Medium priorityRed Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
2 affected packages
resteasy, resteasy3.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
resteasy | Not affected | Not affected | Not affected | Not in release | Not affected |
resteasy3.0 | Not affected | Not affected | Not affected | Vulnerable | Not in release |
CVE-2016-7050
Medium prioritySerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
1 affected package
resteasy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
resteasy | Not affected | Not affected | Not affected | Not in release | Vulnerable |
CVE-2016-6347
Medium priorityCross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1 affected package
resteasy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
resteasy | Not affected | Not affected | Not affected | Not in release | Vulnerable |
CVE-2016-6348
Medium priorityJacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.
1 affected package
resteasy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
resteasy | Not affected | Not affected | Not affected | Not in release | Vulnerable |
CVE-2016-6346
Low priorityRESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.
1 affected package
resteasy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
resteasy | Not affected | Not affected | Not affected | Not in release | Vulnerable |
CVE-2016-6345
Medium priorityRESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
1 affected package
resteasy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
resteasy | Not affected | Not affected | Not affected | Not in release | Vulnerable |
CVE-2014-7839
Medium priorityDocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via...
1 affected package
resteasy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
resteasy | — | — | — | Not in release | Not affected |