CVE-2020-1695
published 2020-05-19CVE-2020-1695: A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.02%
78.8th percentile
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | resteasy | < resteasy3.0 3.0.26-2 (bookworm) | resteasy3.0 3.0.26-2 (bookworm) |
| debian | resteasy3.0 | < resteasy3.0 3.0.26-2 (bookworm) | resteasy3.0 3.0.26-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| red_hat | resteasy | — | — |
| red_hat | resteasy | — | — |
| redhat | resteasy | >= 0 < 3.0.6-3ubuntu0.1~esm1 | 3.0.6-3ubuntu0.1~esm1 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.20.04.1~esm1 | 3.6.2-2ubuntu0.20.04.1~esm1 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.22.04.1~esm1 | 3.6.2-2ubuntu0.22.04.1~esm1 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.24.04.1~esm1 | 3.6.2-2ubuntu0.24.04.1~esm1 |
| redhat | resteasy | >= 3.0.0 < 3.12.0 | 3.12.0 |
| redhat | resteasy | >= 4.0.0 < 4.6.0 | 4.6.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_oracle6.8MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
resteasy, resteasy3.0 vulnerabilities
osv·2025-07-10·CVSS 6.5
CVE-2016-6345 [MEDIUM] resteasy, resteasy3.0 vulnerabilities
resteasy, resteasy3.0 vulnerabilities
It was discovered that RESTEasy made insufficient use of random values in
asynchronous jobs. An attacker could possibly use this issue to steal
user data. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-6345)
It was discovered that RESTEasy enabled a vulnerable GZIP decompression
module by default. An attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-6346)
It was discovered that RESTEasy improperly made use of unsanitized data
while handling certain errors. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS. (CVE-2016-6347)
It was discovered that RESTEasy enabled a vulnerable JSON mani
OSV
resteasy vulnerabilities
osv·2025-03-13·CVSS 6.1
CVE-2020-10688 [MEDIUM] resteasy vulnerabilities
resteasy vulnerabilities
Nikos Papadopoulos discovered that RESTEasy improperly handled URL encoding
when certain errors occur. An attacker could possibly use this issue to
modify the app's behavior for other users through the network.
(CVE-2020-10688)
Mirko Selber discovered that RESTEasy improperly validated user input
during HTTP response construction. This issue could possibly allow an
attacker to cause a denial of service or execute arbitrary code.
(CVE-2020-1695)
It was discovered that RESTEasy unintentionally disclosed potentially
sensitive server information to users during the handling of certain
errors. (CVE-2020-25633)
It was discovered that RESTEasy unintentionally disclosed parts of its code
to users during the handling of certain errors. (CVE-2021-20289)
It was discovere
OSV
Improper Input Validation in RESTEasy
osv·2022-05-24
CVE-2020-1695 [HIGH] Improper Input Validation in RESTEasy
Improper Input Validation in RESTEasy
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
GHSA
Improper Input Validation in RESTEasy
ghsa·2022-05-24
CVE-2020-1695 [HIGH] CWE-20 Improper Input Validation in RESTEasy
Improper Input Validation in RESTEasy
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
OSV
CVE-2020-1695: A flaw was found in all resteasy 3
osv·2020-05-19·CVSS 7.5
CVE-2020-1695 [HIGH] CVE-2020-1695: A flaw was found in all resteasy 3
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
Ubuntu
RESTEasy vulnerabilities
vendor_ubuntu·2025-07-10·CVSS 6.5
CVE-2021-20289 [MEDIUM] RESTEasy vulnerabilities
Title: RESTEasy vulnerabilities
Summary: Several security issues were fixed in resteasy, resteasy3.0.
It was discovered that RESTEasy made insufficient use of random values in
asynchronous jobs. An attacker could possibly use this issue to steal
user data. This issue only affected Ubuntu 14.04 LTS. (CVE-2016-6345)
It was discovered that RESTEasy enabled a vulnerable GZIP decompression
module by default. An attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2016-6346)
It was discovered that RESTEasy improperly made use of unsanitized data
while handling certain errors. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS. (CVE-2016-6347
Ubuntu
RESTEasy vulnerabilities
vendor_ubuntu·2025-03-13·CVSS 6.1
CVE-2020-1695 [MEDIUM] RESTEasy vulnerabilities
Title: RESTEasy vulnerabilities
Summary: Several security issues were fixed in RESTEasy.
Nikos Papadopoulos discovered that RESTEasy improperly handled URL encoding
when certain errors occur. An attacker could possibly use this issue to
modify the app's behavior for other users through the network.
(CVE-2020-10688)
Mirko Selber discovered that RESTEasy improperly validated user input
during HTTP response construction. This issue could possibly allow an
attacker to cause a denial of service or execute arbitrary code.
(CVE-2020-1695)
It was discovered that RESTEasy unintentionally disclosed potentially
sensitive server information to users during the handling of certain
errors. (CVE-2020-25633)
It was discovered that RESTEasy unintentionally disclosed parts of its code
to users during t
Red Hat
resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class
vendor_redhat·2020-04-15·CVSS 7.5
CVE-2020-1695 [HIGH] CWE-20 resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class
resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
A flaw was found in Resteasy, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
Package: resteasy-jaxrs (Red Hat BPM Suite 6) - Out of support scope
Package: resteasy-jaxrs-al
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Mobile (Mobile Application Framework) — CVE-2012-1695
vendor_oracle·2020-01-15·CVSS 6.8
CVE-2012-1695 [MEDIUM] Oracle Oracle Construction and Engineering Risk Matrix: Mobile (Mobile Application Framework) — CVE-2012-1695
Oracle Oracle Construction and Engineering Risk Matrix: Mobile (Mobile Application Framework) vulnerability
CVE: CVE-2012-1695
CVSS: 6.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Debian
CVE-2020-1695: resteasy - A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all re...
vendor_debian·2020·CVSS 7.5
CVE-2020-1695 [HIGH] CVE-2020-1695: resteasy - A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all re...
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
Scope: local
sid: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1695 resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class [fedora-all]
bugzilla·2020-06-09·CVSS 7.5
CVE-2020-1695 [HIGH] CVE-2020-1695 resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class [fedora-all]
CVE-2020-1695 resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2020-2103 jenkins: Exposed session identifiers on user detail object in the whoAmI diagnostic page
bugzilla·2020-01-31·CVSS 5.4
CVE-2020-2103 [MEDIUM] CVE-2020-2103 jenkins: Exposed session identifiers on user detail object in the whoAmI diagnostic page
CVE-2020-2103 jenkins: Exposed session identifiers on user detail object in the whoAmI diagnostic page
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
References:
https://jenkins.io/security/advisory/2020-01-29/#SECURITY-1695
https://www.openwall.com/lists/oss-security/2020/01/29/1
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1797063]
---
"Any security advisory related updates to Jenkins core or the plugins we include in the OpenShift Jenkins master image will only occur in the v3.11 and v4.x branches of this repository."
https://github.com/openshift/jenkins/blob/master/README.md#jenkins-security-advisories-the-master-image-from-this-repository-and-the-oc-b
Bugzilla
CVE-2020-1695 resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class
bugzilla·2019-07-16·CVSS 7.5
CVE-2020-1695 [HIGH] CVE-2020-1695 resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class
CVE-2020-1695 resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class
A flaw was found in resteasy before 4.1.1. An improper input validation in MediaTypeHeaderDelegate.java class results in the class returning an illegal header that will be then integrated in the server's response.
Discussion:
Acknowledgments:
Name: Mirko Selber (Compass Security)
---
This vulnerability is out of security support scope for the following product:
* Red Hat Mobile Application Platform
Please refer to https://access.redhat.com/support/policy/updates/rhmap for more details
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss BPM Suite 6
* Red Hat JBoss BPM Suite 6
* Red Hat JBoss Data Virtualization & Services 6
* Red Hat
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1695https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJDMT443YZWCBS5NS76XZ7TL3GK7BXHL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RX22C6I56BJUER76IIPYHGZIWBQIU3CQ/https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1695https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJDMT443YZWCBS5NS76XZ7TL3GK7BXHL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RX22C6I56BJUER76IIPYHGZIWBQIU3CQ/
2020-05-19
Published