← Back

CVE-2020-25633

nvd nist
Published: Sep 18, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the RESTEasy client call. The highest threat from this vulnerability is to data confidentiality.

Affected (3)

1 product
Resteasy
1 product
Quarkus
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Before 3.14.0
From 4.5.0 to 4.5.6
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.11.6

References (2)

Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.