Cross-site scripting in RESTEasy
Moderate severity
GitHub Reviewed
Published
Jun 15, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 27, 2021
Reviewed
Jun 1, 2021
Published to the GitHub Advisory Database
Jun 15, 2021
Last updated
Feb 1, 2023
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
References