CVE-2017-7561
published 2017-09-13CVE-2017-7561: Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
1.51%
71.7th percentile
Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | resteasy | < resteasy 3.6.2-1 (sid) | resteasy 3.6.2-1 (sid) |
| debian | resteasy3.0 | < resteasy 3.6.2-1 (sid) | resteasy 3.6.2-1 (sid) |
| red_hat_inc | resteasy | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP
ghsa·2022-05-13
CVE-2017-7561 [HIGH] CWE-444 Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP
Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP
Red Hat JBoss EAP version 3.0.7.Final until 3.0.25.Final, 3.5.0.CR1, and 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
OSV
Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP
osv·2022-05-13
CVE-2017-7561 [HIGH] Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP
Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP
Red Hat JBoss EAP version 3.0.7.Final until 3.0.25.Final, 3.5.0.CR1, and 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
OSV
CVE-2017-7561: Red Hat JBoss EAP version 3
osv·2017-09-13·CVSS 7.5
CVE-2017-7561 [HIGH] CVE-2017-7561: Red Hat JBoss EAP version 3
Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
Red Hat
resteasy: Vary header not added by CORS filter leading to cache poisoning
vendor_redhat·2017-08-22·CVSS 7.5
CVE-2017-7561 [HIGH] CWE-345 resteasy: Vary header not added by CORS filter leading to cache poisoning
resteasy: Vary header not added by CORS filter leading to cache poisoning
Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
It was discovered that the CORS Filter did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.
Package: resteasy (Red Hat JBoss A-MQ 6) - Will not fix
Package: resteasy (Red Hat JBoss Data Grid 7) - Not affected
Package: resteasy (Red Hat JBoss Data Virtualization 6) - Not affected
Package: resteasy (Red Hat JBoss Fuse 6) - Will not fix
Package: resteasy (Red Hat JBoss Operations Network 3) - Not affected
Package: resteasy (R
Debian
CVE-2017-7561: resteasy - Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a se...
vendor_debian·2017·CVSS 7.5
CVE-2017-7561 [HIGH] CVE-2017-7561: resteasy - Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a se...
Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
Scope: local
sid: resolved (fixed in 3.6.2-1)
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/100465https://access.redhat.com/errata/RHSA-2018:0002https://access.redhat.com/errata/RHSA-2018:0003https://access.redhat.com/errata/RHSA-2018:0004https://access.redhat.com/errata/RHSA-2018:0005https://access.redhat.com/errata/RHSA-2018:0478https://access.redhat.com/errata/RHSA-2018:0479https://access.redhat.com/errata/RHSA-2018:0480https://access.redhat.com/errata/RHSA-2018:0481https://issues.jboss.org/browse/RESTEASY-1704http://www.securityfocus.com/bid/100465https://access.redhat.com/errata/RHSA-2018:0002https://access.redhat.com/errata/RHSA-2018:0003https://access.redhat.com/errata/RHSA-2018:0004https://access.redhat.com/errata/RHSA-2018:0005https://access.redhat.com/errata/RHSA-2018:0478https://access.redhat.com/errata/RHSA-2018:0479https://access.redhat.com/errata/RHSA-2018:0480https://access.redhat.com/errata/RHSA-2018:0481https://issues.jboss.org/browse/RESTEASY-1704
2017-09-13
Published