cbcvebase.
CVE-2020-25633
published 2020-09-18

CVE-2020-25633: A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive…

PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.21%
65.0th percentile
A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the RESTEasy client call. The highest threat from this vulnerability is to data confidentiality.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianresteasy
debianresteasy3.0
quarkusquarkus<= 1.11.6
red_hatresteasy-client
redhatresteasy< 3.14.03.14.0
redhatresteasy>= 0 < 3.0.6-3ubuntu0.1~esm13.0.6-3ubuntu0.1~esm1
redhatresteasy>= 0 < 3.6.2-2ubuntu0.20.04.1~esm13.6.2-2ubuntu0.20.04.1~esm1
redhatresteasy>= 0 < 3.6.2-2ubuntu0.22.04.1~esm13.6.2-2ubuntu0.22.04.1~esm1
redhatresteasy>= 0 < 3.6.2-2ubuntu0.24.04.1~esm13.6.2-2ubuntu0.24.04.1~esm1
redhatresteasy4.5.0 – 4.5.6

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.