cbcvebase.
CVE-2020-25724
published 2021-05-26

CVE-2020-25724: A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged…

PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.63%
46.1th percentile
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianresteasy
debianresteasy3.0
quarkusquarkus< 1.11.21.11.2
redhatresteasy< 2.0.02.0.0
redhatresteasy
redhatresteasy
redhatresteasy>= 0 < 3.6.2-23.6.2-2
redhatresteasy>= 0 < 3.6.2-23.6.2-2
redhatresteasy>= 0 < 3.6.2-23.6.2-2

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.