CVE-2020-10688
Last modified
CVE-2020-10688 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.. EPSS estimates a 1.39% chance of exploitation in the next 30 days.
Description
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Fuse | 1.0 |
| Redhat | Jboss Enterprise Application Platform | All versions |
| Redhat | Openshift Application Runtimes | All versions |
| Redhat | Resteasy | < 3.11.1 |
| Redhat | Resteasy | >= 4.5.0, < 4.5.3 |
| Redhat | Jboss Enterprise Application Platform | 7.3 |
| Redhat | Jboss Enterprise Application Platform | 7.4 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1814974Issue Tracking, Patch, Vendor Advisory
- https://github.com/quarkusio/quarkus/issues/7248Exploit, Issue Tracking, Third Party Advisory
- https://issues.redhat.com/browse/RESTEASY-2519Issue Tracking, Permissions Required, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210706-0008/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1814974Issue Tracking, Patch, Vendor Advisory
- https://github.com/quarkusio/quarkus/issues/7248Exploit, Issue Tracking, Third Party Advisory
- https://issues.redhat.com/browse/RESTEASY-2519Issue Tracking, Permissions Required, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210706-0008/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10688?
How severe is CVE-2020-10688?
How do I fix CVE-2020-10688?
Are you affected by CVE-2020-10688?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
