cbcvebase.

Redhat Resteasy vulnerabilities

17 known vulnerabilities affecting redhat/resteasy.

Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM11

Vulnerabilities

Page 1 of 1
CVE-2016-7050P2CRITICALCVSS 9.8≥ 0, < 3.0.6-3ubuntu0.1~esm12017-06-08
CVE-2016-7050 [CRITICAL] CVE-2016-7050: SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Re SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
osv
CVE-2016-9606P3HIGHCVSS 8.1≤ 3.1.12018-03-09
CVE-2016-9606 [HIGH] CWE-20 CVE-2016-9606: JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, result JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.
nvd
CVE-2014-3490P3HIGHCVSS 7.5≥ 2.3.1, ≤ 2.3.7.2≥ 3.0.0, < 3.0.9+1 more2014-08-19
CVE-2014-3490 [HIGH] CVE-2014-3490: RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Applicatio RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to a
nvd
CVE-2020-1695P3HIGHCVSS 7.5≥ 3.0.0, < 3.12.0≥ 4.0.0, < 4.6.02020-05-19
CVE-2020-1695 [HIGH] CWE-20 CVE-2020-1695: A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x version A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
nvd
CVE-2018-1051P3HIGHCVSS 8.1v3.0.22v3.1.22018-01-25
CVE-2018-1051 [HIGH] CVE-2018-1051: It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unm It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.
nvd
CVE-2014-7839P3MEDIUMCVSS 6.4v2.3.7v3.0.92014-11-25
CVE-2014-7839 [MEDIUM] CWE-20 CVE-2014-7839: DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
nvd
CVE-2020-14326P3HIGHCVSS 7.5≥ 4.2.0, < 4.5.6vRESTEasy 4.5.6.Final2021-06-02
CVE-2020-14326 [HIGH] CWE-400 CVE-2020-14326: A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with higher CPU time spent searching and adding the entry. This flaw allows an attacker to cause a denial of service.
nvd
CVE-2012-0818P4MEDIUMCVSS 5.0≤ 2.3.0v1.0.0+11 more2012-11-23
CVE-2012-0818 [MEDIUM] CWE-200 CVE-2012-0818: RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity referen RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity (XXE) injection attack.
nvd
CVE-2011-5245P4MEDIUMCVSS 5.0≤ 2.3.1v1.0.0+12 more2012-11-23
CVE-2011-5245 [MEDIUM] CWE-200 CVE-2011-5245: The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote a The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.
nvd
CVE-2016-6345P4MEDIUMCVSS 6.5≥ 0, < 3.0.6-3ubuntu0.1~esm12025-07-10
CVE-2016-6345 [MEDIUM] resteasy, resteasy3.0 vulnerabilities resteasy, resteasy3.0 vulnerabilities It was discovered that RESTEasy made insufficient use of random values in asynchronous jobs. An attacker could possibly use this issue to steal user data. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-6345) It was discovered that RESTEasy enabled a vulnerable GZIP decompression module by default. An attacker could possibly use this issue to cause a denial of service. This issue only affect
osv
CVE-2021-20289P4MEDIUMCVSS 5.3≤ 4.6.0vresteasy 3.11.5.Final, resteasy 3.15.2.Final, resteasy 4.5.10.Final, resteasy 4.6.1.Final, resteasy 4.6.2.Final2021-03-26
CVE-2021-20289 [MEDIUM] CWE-209 CVE-2021-20289: A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and m A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confide
nvdosv
CVE-2024-9622P4MEDIUMCVSS 5.3≥ 0, < 3.0.6-3ubuntu0.1~esm1≥ 0, < 3.6.2-2ubuntu0.20.04.1~esm1+2 more2024-10-08
CVE-2024-9622 [MEDIUM] CVE-2024-9622: A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE state. As a result, any subsequent legitimate requests
osv
CVE-2020-10688P4MEDIUMCVSS 6.1fixed in 3.11.1≥ 4.5.0, < 4.5.3+1 more2021-05-27
CVE-2020-10688 [MEDIUM] CWE-79 CVE-2020-10688: A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4 A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
nvdosv
CVE-2020-25633P4MEDIUMCVSS 5.3fixed in 3.14.0≥ 4.5.0, ≤ 4.5.62020-09-18
CVE-2020-25633 [MEDIUM] CWE-209 CVE-2020-25633: A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow clie A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the RESTEasy client call. The highest threat from this vulnerability is to data confidentiality.
nvd
CVE-2021-20293P4MEDIUMCVSS 6.1≤ 4.6.0vAll versions of RESTEasy up to 4.6.0.Final2021-06-10
CVE-2021-20293 [MEDIUM] CWE-79 CVE-2021-20293: A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.ws.rs.PathParam without any @Produces MediaType. This flaw allows an attacker to launch a reflected XSS attack. The highest threat from this vulnerability is to data confiden
nvd
CVE-2020-25724P4MEDIUMCVSS 4.3fixed in 2.0.0v2.0.0+1 more2021-05-26
CVE-2020-25724 [MEDIUM] CWE-567 CVE-2020-25724: A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.
nvdosv
CVE-2023-0482P4MEDIUMCVSS 5.5v3.15.4v4.7.7+3 more2023-02-17
CVE-2023-0482 [MEDIUM] CWE-378 CVE-2023-0482: In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and M In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
nvd
Redhat Resteasy vulnerabilities | cvebase