Resteasy
Red Hat · 19 CVEs
RESTEasy: creation of insecure temp files
Feb 17, 2023
RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack
Jun 10, 2021
RESTEasy: Caching routes in RootNode may result in DoS
Jun 2, 2021
RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack
May 27, 2021
resteasy: information disclosure via HTTP response reuse
May 26, 2021
resteasy: Error message exposes endpoint class information
Mar 26, 2021
resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling
Sep 18, 2020
resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class
May 19, 2020
Resteasy: Yaml unmarshalling vulnerable to RCE
Mar 9, 2018
resteasy: Unsafe unmarshalling in YamlProvider allows code execution
Jan 25, 2018
resteasy: Vary header not added by CORS filter leading to cache poisoning
Sep 13, 2017
RESTEasy: Use of the default exception handler in RESTEasy can lead to reflected XSS attack
Apr 20, 2017
RESTEasy: Use of JacksonJsonpInterceptor in RESTEasy can lead to Cross Site Script Inclusion attack
Apr 12, 2017
RESTEasy: Abuse of GZIPInterceptor in RESTEasy can lead to denial of service attack
Sep 7, 2016
RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality
Sep 7, 2016
RESTeasy: External entities expanded by DocumentProvider
Nov 25, 2014
RESTEasy: XXE via parameter entities
Aug 19, 2014
RESTEasy: XML eXternal Entity (XXE) flaw
Nov 23, 2012
RESTEasy: XML eXternal Entity (XXE) flaw
Nov 23, 2012
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-0482 | RESTEasy: creation of insecure temp files | MEDIUM | 0.26% | Feb 17, 2023 |
| CVE-2021-20293 | RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack | HIGH | 0.86% | Jun 10, 2021 |
| CVE-2020-14326 | RESTEasy: Caching routes in RootNode may result in DoS | HIGH | 1.22% | Jun 2, 2021 |
| CVE-2020-10688 | RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack | MEDIUM | 1.39% | May 27, 2021 |
| CVE-2020-25724 | resteasy: information disclosure via HTTP response reuse | MEDIUM | 0.63% | May 26, 2021 |
| CVE-2021-20289 | resteasy: Error message exposes endpoint class information | MEDIUM | 1.40% | Mar 26, 2021 |
| CVE-2020-25633 | resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling | MEDIUM | 1.18% | Sep 18, 2020 |
| CVE-2020-1695 | resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class | HIGH | 2.02% | May 19, 2020 |
| CVE-2016-9606 | Resteasy: Yaml unmarshalling vulnerable to RCE | HIGH | 5.97% | Mar 9, 2018 |
| CVE-2018-1051 | resteasy: Unsafe unmarshalling in YamlProvider allows code execution | HIGH | 1.31% | Jan 25, 2018 |
| CVE-2017-7561 | resteasy: Vary header not added by CORS filter leading to cache poisoning | HIGH | 1.51% | Sep 13, 2017 |
| CVE-2016-6347 | RESTEasy: Use of the default exception handler in RESTEasy can lead to reflected XSS attack | MEDIUM | 1.87% | Apr 20, 2017 |
| CVE-2016-6348 | RESTEasy: Use of JacksonJsonpInterceptor in RESTEasy can lead to Cross Site Script Inclusion attack | MEDIUM | 1.57% | Apr 12, 2017 |
| CVE-2016-6346 | RESTEasy: Abuse of GZIPInterceptor in RESTEasy can lead to denial of service attack | HIGH | 5.60% | Sep 7, 2016 |
| CVE-2016-6345 | RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality | MEDIUM | 1.77% | Sep 7, 2016 |
| CVE-2014-7839 | RESTeasy: External entities expanded by DocumentProvider | MEDIUM | 1.96% | Nov 25, 2014 |
| CVE-2014-3490 | RESTEasy: XXE via parameter entities | HIGH | 4.57% | Aug 19, 2014 |
| CVE-2012-0818 | RESTEasy: XML eXternal Entity (XXE) flaw | MEDIUM | 3.21% | Nov 23, 2012 |
| CVE-2011-5245 | RESTEasy: XML eXternal Entity (XXE) flaw | MEDIUM | 3.21% | Nov 23, 2012 |
Showing 1 to 19 of 19 CVEs