Lucene search

K
osvGoogleOSV:GHSA-VXHJ-3X7P-JXP5
HistoryMay 17, 2022 - 3:49 a.m.

Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy

2022-05-1703:49:16
Google
osv.dev
5
sensitive information exposure
unauthorized actor
remote authentication
random values
security flaw
software vulnerability
resteasy

EPSS

0.001

Percentile

45.1%

RESTEasy allows remote authenticated users to obtain sensitive information by leveraging “insufficient use of random values” in async jobs.

EPSS

0.001

Percentile

45.1%