Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Amazon Linux AMI 2: CVE-2021-20289: Security patch for resteasy-base (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Mar 26, 2021
Added
Jan 10, 2024
Modified
May 20, 2026

Description

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.

Solutions

amazon-linux-ami-2-upgrade-resteasy-baseamazon-linux-ami-2-upgrade-resteasy-base-atom-provideramazon-linux-ami-2-upgrade-resteasy-base-clientamazon-linux-ami-2-upgrade-resteasy-base-jackson-provideramazon-linux-ami-2-upgrade-resteasy-base-javadocamazon-linux-ami-2-upgrade-resteasy-base-jaxb-provideramazon-linux-ami-2-upgrade-resteasy-base-jaxrsamazon-linux-ami-2-upgrade-resteasy-base-jaxrs-allamazon-linux-ami-2-upgrade-resteasy-base-jaxrs-apiamazon-linux-ami-2-upgrade-resteasy-base-jettison-provideramazon-linux-ami-2-upgrade-resteasy-base-providers-pomamazon-linux-ami-2-upgrade-resteasy-base-resteasy-pomamazon-linux-ami-2-upgrade-resteasy-base-tjws
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.