CVE-2020-10688
published 2021-05-27CVE-2020-10688: A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.39%
69.3th percentile
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | resteasy | < resteasy3.0 3.0.26-4 (bookworm) | resteasy3.0 3.0.26-4 (bookworm) |
| debian | resteasy3.0 | < resteasy3.0 3.0.26-4 (bookworm) | resteasy3.0 3.0.26-4 (bookworm) |
| redhat | fuse | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | resteasy | < 3.11.1 | 3.11.1 |
| redhat | resteasy | — | — |
| redhat | resteasy | >= 0 < 3.0.6-3ubuntu0.1~esm1 | 3.0.6-3ubuntu0.1~esm1 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.20.04.1~esm1 | 3.6.2-2ubuntu0.20.04.1~esm1 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.22.04.1~esm1 | 3.6.2-2ubuntu0.22.04.1~esm1 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.24.04.1~esm1 | 3.6.2-2ubuntu0.24.04.1~esm1 |
| redhat | resteasy | >= 4.5.0 < 4.5.3 | 4.5.3 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
RESTEasy vulnerabilities
vendor_ubuntu·2025-07-10·CVSS 6.5
CVE-2021-20289 [MEDIUM] RESTEasy vulnerabilities
Title: RESTEasy vulnerabilities
Summary: Several security issues were fixed in resteasy, resteasy3.0.
It was discovered that RESTEasy made insufficient use of random values in
asynchronous jobs. An attacker could possibly use this issue to steal
user data. This issue only affected Ubuntu 14.04 LTS. (CVE-2016-6345)
It was discovered that RESTEasy enabled a vulnerable GZIP decompression
module by default. An attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2016-6346)
It was discovered that RESTEasy improperly made use of unsanitized data
while handling certain errors. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS. (CVE-2016-6347
Ubuntu
RESTEasy vulnerabilities
vendor_ubuntu·2025-03-13·CVSS 6.1
CVE-2020-1695 [MEDIUM] RESTEasy vulnerabilities
Title: RESTEasy vulnerabilities
Summary: Several security issues were fixed in RESTEasy.
Nikos Papadopoulos discovered that RESTEasy improperly handled URL encoding
when certain errors occur. An attacker could possibly use this issue to
modify the app's behavior for other users through the network.
(CVE-2020-10688)
Mirko Selber discovered that RESTEasy improperly validated user input
during HTTP response construction. This issue could possibly allow an
attacker to cause a denial of service or execute arbitrary code.
(CVE-2020-1695)
It was discovered that RESTEasy unintentionally disclosed potentially
sensitive server information to users during the handling of certain
errors. (CVE-2020-25633)
It was discovered that RESTEasy unintentionally disclosed parts of its code
to users during t
Red Hat
RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack
vendor_redhat·2020-02-18·CVSS 6.1
CVE-2020-10688 [MEDIUM] CWE-79 RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack
RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
A cross-site scripting (XSS) flaw was found in RESTEasy, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
Package: resteasy (Red Hat JBoss Fuse 6) - Out of support scope
Package: resteasy (Red Hat OpenShift Application Runtimes) - Affected
Package: resteasy (Red Hat support for Spring Boot) - Affected
Debian
CVE-2020-10688: resteasy - A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11....
vendor_debian·2020·CVSS 6.1
CVE-2020-10688 [MEDIUM] CVE-2020-10688: resteasy - A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11....
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
Scope: local
sid: open
OSV
resteasy, resteasy3.0 vulnerabilities
osv·2025-07-10·CVSS 6.5
CVE-2016-6345 [MEDIUM] resteasy, resteasy3.0 vulnerabilities
resteasy, resteasy3.0 vulnerabilities
It was discovered that RESTEasy made insufficient use of random values in
asynchronous jobs. An attacker could possibly use this issue to steal
user data. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-6345)
It was discovered that RESTEasy enabled a vulnerable GZIP decompression
module by default. An attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-6346)
It was discovered that RESTEasy improperly made use of unsanitized data
while handling certain errors. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS. (CVE-2016-6347)
It was discovered that RESTEasy enabled a vulnerable JSON mani
OSV
resteasy vulnerabilities
osv·2025-03-13·CVSS 6.1
CVE-2020-10688 [MEDIUM] resteasy vulnerabilities
resteasy vulnerabilities
Nikos Papadopoulos discovered that RESTEasy improperly handled URL encoding
when certain errors occur. An attacker could possibly use this issue to
modify the app's behavior for other users through the network.
(CVE-2020-10688)
Mirko Selber discovered that RESTEasy improperly validated user input
during HTTP response construction. This issue could possibly allow an
attacker to cause a denial of service or execute arbitrary code.
(CVE-2020-1695)
It was discovered that RESTEasy unintentionally disclosed potentially
sensitive server information to users during the handling of certain
errors. (CVE-2020-25633)
It was discovered that RESTEasy unintentionally disclosed parts of its code
to users during the handling of certain errors. (CVE-2021-20289)
It was discovere
OSV
Cross-site scripting in RESTEasy
osv·2021-06-15
CVE-2020-10688 [MEDIUM] Cross-site scripting in RESTEasy
Cross-site scripting in RESTEasy
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
GHSA
Cross-site scripting in RESTEasy
ghsa·2021-06-15
CVE-2020-10688 [MEDIUM] CWE-79 Cross-site scripting in RESTEasy
Cross-site scripting in RESTEasy
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
OSV
CVE-2020-10688: A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3
osv·2021-05-27·CVSS 6.1
CVE-2020-10688 [MEDIUM] CVE-2020-10688: A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1814974https://github.com/quarkusio/quarkus/issues/7248https://issues.redhat.com/browse/RESTEASY-2519https://security.netapp.com/advisory/ntap-20210706-0008/https://bugzilla.redhat.com/show_bug.cgi?id=1814974https://github.com/quarkusio/quarkus/issues/7248https://issues.redhat.com/browse/RESTEASY-2519https://security.netapp.com/advisory/ntap-20210706-0008/
2021-05-27
Published