VDB
RHSA-2021%3A2858
RHSA-2021%3A2858
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A flaw was found in the RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. This flaw allows client users to obtain the server's potentially sensitive information when the server receives the WebApplicationException from the RESTEasy client call. The highest threat from this vulnerability is to confidentiality.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | org.wildfly.security.wildfly-elytron-json-util-1.15.3.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | 1.15.3, * |
| Red Hat | None.promise-7.3.1 as a component of Red Hat JBoss Enterprise Application Platform | *, 7.3.1 |
| Red Hat | None.unist-util-find-all-after-1.0.4 as a component of Red Hat JBoss Enterprise Application Platform | 1.0.4, None.unist-util-find-all-after-1.0.4 |
| Red Hat | None.estraverse-4.1.0 as a component of Red Hat JBoss Enterprise Application Platform | None.estraverse-4.1.0, 4.1.0 |
| Red Hat | com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.12.1.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.12.1.redhat-00001.pom, 2.12.1 |
| Red Hat | org.wildfly.security.wildfly-elytron-sasl-1.15.3.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | 1.15.3, org.wildfly.security.wildfly-elytron-sasl-1.15.3.Final-redhat-00001.jar |
| Red Hat | None.object.map-1.0.1 as a component of Red Hat JBoss Enterprise Application Platform | 1.0.1, None.object.map-1.0.1 |
| Red Hat | None.pretty-bytes-3.0.1 as a component of Red Hat JBoss Enterprise Application Platform | None.pretty-bytes-3.0.1, 3.0.1 |
| Red Hat | None.path-root-0.1.1 as a component of Red Hat JBoss Enterprise Application Platform | None.path-root-0.1.1, 0.1.1 |
| Red Hat | org.apache.activemq.artemis-cli-2.16.0.redhat-00022.jar as a component of Red Hat JBoss Enterprise Application Platform | 2.16.0, org.apache.activemq.artemis-cli-2.16.0.redhat-00022.jar |
| Red Hat | @types.d3-timer-1.0.7 as a component of Red Hat JBoss Enterprise Application Platform | @types.d3-timer-1.0.7, 1.0.7 |
| Red Hat | org.picketbox.common-spi-5.0.3.Final-redhat-00007.pom as a component of Red Hat JBoss Enterprise Application Platform | 5.0.3, org.picketbox.common-spi-5.0.3.Final-redhat-00007.pom |
| Red Hat | None.redent-1.0.0 as a component of Red Hat JBoss Enterprise Application Platform | None.redent-1.0.0, 1.0.0 |
| Red Hat | xerces.xercesImpl-2.12.0.SP03-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | *, 2.12.0 |
| Red Hat | org.jboss.metadata.jboss-metadata-appclient-13.0.0.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | org.jboss.metadata.jboss-metadata-appclient-13.0.0.Final-redhat-00001.jar, 13.0.0 |
| Red Hat | org.jboss.ws.cxf.jbossws-cxf-transports-undertow-5.4.2.Final-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | 5.4.2, * |
| Red Hat | None.sprintf-js-1.0.3 as a component of Red Hat JBoss Enterprise Application Platform | None.sprintf-js-1.0.3, 1.0.3 |
| Red Hat | None.rw-1.3.3 as a component of Red Hat JBoss Enterprise Application Platform | 1.3.3, * |
| Red Hat | None.escape-html-1.0.3 as a component of Red Hat JBoss Enterprise Application Platform | *, 1.0.3 |
| Red Hat | None.object-visit-1.0.1 as a component of Red Hat JBoss Enterprise Application Platform | 1.0.1, None.object-visit-1.0.1 |
…and 2017 more
Timeline
- Jul 21, 2021 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2021:2858 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=7.4 advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4 advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1879042 issue
- https://issues.redhat.com/browse/JBEAP-21120 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2858.json advisory
- https://access.redhat.com/security/cve/CVE-2020-25633 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-25633 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25633 advisory