Search CVE reports


Toggle filters

11 – 18 of 18 results


CVE-2018-1051

Low priority
Vulnerable

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.

2 affected packages

resteasy, resteasy3.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
resteasy Not affected Not affected Not affected Not in release Vulnerable
resteasy3.0 Not affected Not affected Not affected Not affected Not in release
Show less packages

CVE-2017-7561

Medium priority
Vulnerable

Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.

2 affected packages

resteasy, resteasy3.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
resteasy Not affected Not affected Not affected Not in release Not affected
resteasy3.0 Not affected Not affected Not affected Vulnerable Not in release
Show less packages

CVE-2016-7050

Medium priority
Vulnerable

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.

1 affected package

resteasy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
resteasy Not affected Not affected Not affected Not in release Vulnerable
Show less packages

CVE-2016-6347

Medium priority
Vulnerable

Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1 affected package

resteasy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
resteasy Not affected Not affected Not affected Not in release Vulnerable
Show less packages

CVE-2016-6348

Medium priority
Vulnerable

JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.

1 affected package

resteasy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
resteasy Not affected Not affected Not affected Not in release Vulnerable
Show less packages

CVE-2016-6346

Low priority
Vulnerable

RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.

1 affected package

resteasy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
resteasy Not affected Not affected Not affected Not in release Vulnerable
Show less packages

CVE-2016-6345

Medium priority
Vulnerable

RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.

1 affected package

resteasy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
resteasy Not affected Not affected Not affected Not in release Vulnerable
Show less packages

CVE-2014-7839

Medium priority
Ignored

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via...

1 affected package

resteasy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
resteasy Not in release Not affected
Show less packages