Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-20293
HistoryJun 10, 2021 - 12:15 p.m.

Cross site scripting

2021-06-1012:15:00
PRIOn knowledge base
www.prio-n.com
3

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.3%

A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.ws.rs.PathParam without any @Produces MediaType. This flaw allows an attacker to launch a reflected XSS attack. The highest threat from this vulnerability is to data confidentiality and integrity.

CPENameOperatorVersion
resteasyle4.6.0

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.3%