← Back

CVE-2020-10688

nvd nist
Published: May 27, 2021Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.

Affected (7)

4 products
Fuse
Openshift Application Runtimes
Resteasy
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.0
All versions
All versions
Redhat
Before 3.11.1
From 4.5.0 to 4.5.3
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 7.3
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 6.0
Configuration C
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 7.4
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 7.0
Redhat
Enterprise Linux
Version 8.0

References (8)

Source: secalert@redhat.com
Issue TrackingPatchVendor Advisory
Source: secalert@redhat.com
ExploitIssue TrackingThird Party Advisory
Source: secalert@redhat.com
Issue TrackingPermissions RequiredVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPermissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.