← Back

CVE-2020-1695

nvd nist
Published: May 19, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.

Affected (4)

1 product
Resteasy
1 product
Fedora
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
From 3.0.0 to 3.12.0
From 4.0.0 to 4.6.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33

Timeline

No history available yet.