Red Hat / Resteasy
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-0482 | RESTEasy: creation of insecure temp files | MEDIUM | 5.5 | Feb 17, 2023 |
| CVE-2021-20293 | RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack | HIGH | 6.1 | Jun 10, 2021 |
| CVE-2020-14326 | RESTEasy: Caching routes in RootNode may result in DoS | HIGH | 7.5 | Jun 2, 2021 |
| CVE-2020-10688 | RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack | MEDIUM | 6.1 | May 27, 2021 |
| CVE-2020-25724 | resteasy: information disclosure via HTTP response reuse | MEDIUM | 4.3 | May 26, 2021 |
| CVE-2021-20289 | resteasy: Error message exposes endpoint class information | MEDIUM | 5.3 | Mar 26, 2021 |
| CVE-2020-25633 | resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling | MEDIUM | 5.3 | Sep 18, 2020 |
| CVE-2020-1695 | resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class | HIGH | 7.5 | May 19, 2020 |
| CVE-2016-9606 | Resteasy: Yaml unmarshalling vulnerable to RCE | HIGH | 8.1 | Mar 9, 2018 |
| CVE-2018-1051 | resteasy: Unsafe unmarshalling in YamlProvider allows code execution | HIGH | 8.1 | Jan 25, 2018 |
| CVE-2017-7561 | resteasy: Vary header not added by CORS filter leading to cache poisoning | HIGH | 7.5 | Sep 13, 2017 |
| CVE-2016-6347 | RESTEasy: Use of the default exception handler in RESTEasy can lead to reflected XSS attack | MEDIUM | 6.1 | Apr 20, 2017 |
| CVE-2016-6348 | RESTEasy: Use of JacksonJsonpInterceptor in RESTEasy can lead to Cross Site Script Inclusion attack | MEDIUM | 6.1 | Apr 12, 2017 |
| CVE-2016-6346 | RESTEasy: Abuse of GZIPInterceptor in RESTEasy can lead to denial of service attack | HIGH | 7.5 | Sep 7, 2016 |
| CVE-2016-6345 | RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality | MEDIUM | 6.5 | Sep 7, 2016 |
| CVE-2014-7839 | RESTeasy: External entities expanded by DocumentProvider | MEDIUM | 6.4 | Nov 25, 2014 |
| CVE-2014-3490 | RESTEasy: XXE via parameter entities | HIGH | 7.5 | Aug 19, 2014 |
| CVE-2012-0818 | RESTEasy: XML eXternal Entity (XXE) flaw | MEDIUM | 5.0 | Nov 23, 2012 |
| CVE-2011-5245 | RESTEasy: XML eXternal Entity (XXE) flaw | MEDIUM | 5.0 | Nov 23, 2012 |
Showing 1 to 19 of 19 CVEs