VDB

CVE-2020-10688

CVE-2020-10688 PUBLISHED CVSS 6.099999904632568 MEDIUM

A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.

EPSS 1.39% · 71.2th percentile

Risk Scores

CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
1.39%
71.2th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10resteasy3.6.2-3, 0
Ubuntu:22.04:LTSresteasy3.03.0.26-2, 3.0.26-3, 0
Ubuntu:Pro:20.04:LTSresteasy0, 3.6.2-2
Ubuntu:Pro:22.04:LTSresteasy0, 3.6.2-2
Ubuntu:Pro:20.04:LTSresteasy3.00, 3.0.26-1
Ubuntu:Pro:24.04:LTSresteasy0, 3.6.2-2
Ubuntu:Pro:16.04:LTSresteasy3.0.6-3, 0
Ubuntu:Pro:18.04:LTSresteasy3.03.0.26-1~18.04, 3.0.19-2, 3.0.19-1

Timeline

  • Jun 11, 2020 CVE Published
  • May 28, 2021 EPSS Score
  • Jul 31, 2021 EPSS Score
  • Sep 30, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 1, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 3, 2022 EPSS Score
  • Jun 4, 2022 EPSS Score
  • Oct 7, 2022 EPSS Score
  • Dec 7, 2022 EPSS Score
  • Feb 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›