Red Hat, Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with resteasy.
Products
Clear product- keycloak6 vulnerabilities
- 389-ds-base3 vulnerabilities
- ceph3 vulnerabilities
- Gluster Storage for RHEL 63 vulnerabilities
- postgresql3 vulnerabilities
- resteasy3 vulnerabilities
- Ansible Tower2 vulnerabilities
- etcd2 vulnerabilities
- GlusterFS2 vulnerabilities
- Moodle2 vulnerabilities
- Wildfly2 vulnerabilities
- ansible1 vulnerability
- atomic-openshift1 vulnerability
- augeas1 vulnerability
- Cairo1 vulnerability
- CloudForms1 vulnerability
- curl1 vulnerability
- cygwin1 vulnerability
- dnsdist1 vulnerability
- DPDK1 vulnerability
- EAP-51 vulnerability
- fedora-arm-installer1 vulnerability
- hawtio1 vulnerability
- hibernate-validator1 vulnerability
- HornetQ/Artemis1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2016-9606HIGH | JBoss RESTEasy vulnerable to Improper Input ValidationJBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions. CWE-20Mar 9, 2018 | CVSS8.1v3.0 | EPSS6.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-1051HIGH | Deserialization of Untrusted Data in org.jboss.resteasy:resteasy-yaml-providerIt was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider. | CVSS8.1v3.0 | EPSS1.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-7561HIGH | Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAPRed Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact. | CVSS7.5v3.0 | EPSS1.51% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |