CVE-2020-25724
published 2021-05-26CVE-2020-25724: A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.63%
46.1th percentile
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | resteasy | — | — |
| debian | resteasy3.0 | — | — |
| quarkus | quarkus | < 1.11.2 | 1.11.2 |
| redhat | resteasy | < 2.0.0 | 2.0.0 |
| redhat | resteasy | — | — |
| redhat | resteasy | — | — |
| redhat | resteasy | >= 0 < 3.6.2-2 | 3.6.2-2 |
| redhat | resteasy | >= 0 < 3.6.2-2 | 3.6.2-2 |
| redhat | resteasy | >= 0 < 3.6.2-2 | 3.6.2-2 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
resteasy: information disclosure via HTTP response reuse
vendor_redhat·2020-11-16·CVSS 4.3
CVE-2020-25724 [MEDIUM] CWE-567 resteasy: information disclosure via HTTP response reuse
resteasy: information disclosure via HTTP response reuse
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity.
Debian
CVE-2020-25724: resteasy - A flaw was found in RESTEasy, where an incorrect response to an HTTP request is ...
vendor_debian·2020·CVSS 4.3
CVE-2020-25724 [MEDIUM] CVE-2020-25724: resteasy - A flaw was found in RESTEasy, where an incorrect response to an HTTP request is ...
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.
Scope: local
sid: resolved
GHSA
Unsynchronized Access to Shared Data in a Multithreaded Context in RESTEasy
ghsa·2021-06-08
CVE-2020-25724 [MEDIUM] CWE-567 Unsynchronized Access to Shared Data in a Multithreaded Context in RESTEasy
Unsynchronized Access to Shared Data in a Multithreaded Context in RESTEasy
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.
OSV
Unsynchronized Access to Shared Data in a Multithreaded Context in RESTEasy
osv·2021-06-08
CVE-2020-25724 [MEDIUM] Unsynchronized Access to Shared Data in a Multithreaded Context in RESTEasy
Unsynchronized Access to Shared Data in a Multithreaded Context in RESTEasy
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.
OSV
CVE-2020-25724: A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided
osv·2021-05-26·CVSS 4.3
CVE-2020-25724 [MEDIUM] CVE-2020-25724: A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-26
Published