A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade resteasy3.0 | Jul 30, 2024 | May 27, 2021 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Feb 18, 2020 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | May 27, 2021 |
| Ubuntu | — | Upgrade libresteasy-java (Ubuntu Pro)Upgrade libresteasy3.0-javaUpgrade libresteasy3.0-java (Ubuntu Pro)Upgrade libresteasy-java | Mar 14, 2025 | May 27, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub