Lucene search

K
cvelistRedhatCVELIST:CVE-2021-20289
HistoryMar 26, 2021 - 4:28 p.m.

CVE-2021-20289

2021-03-2616:28:44
CWE-209
redhat
www.cve.org
8
resteasy
disclosure
endpoint名称
method names
data confidentiality

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

30.5%

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method’s parameter value. The highest threat from this vulnerability is to data confidentiality.

CNA Affected

[
  {
    "product": "resteasy",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "resteasy 3.11.5.Final, resteasy 3.15.2.Final, resteasy 4.5.10.Final, resteasy 4.6.1.Final, resteasy 4.6.2.Final"
      }
    ]
  }
]

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

30.5%