VDB

RHSA-2021%3A2858

RHSA-2021%3A2858 PUBLISHED CVSS 5.300000190734863 MEDIUM

A flaw was found in the RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. This flaw allows client users to obtain the server's potentially sensitive information when the server receives the WebApplicationException from the RESTEasy client call. The highest threat from this vulnerability is to confidentiality.

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
Red Hatorg.wildfly.security.wildfly-elytron-json-util-1.15.3.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform 1.15.3, *
Red HatNone.promise-7.3.1 as a component of Red Hat JBoss Enterprise Application Platform *, 7.3.1
Red HatNone.unist-util-find-all-after-1.0.4 as a component of Red Hat JBoss Enterprise Application Platform 1.0.4, None.unist-util-find-all-after-1.0.4
Red HatNone.estraverse-4.1.0 as a component of Red Hat JBoss Enterprise Application Platform None.estraverse-4.1.0, 4.1.0
Red Hatcom.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.12.1.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.12.1.redhat-00001.pom, 2.12.1
Red Hatorg.wildfly.security.wildfly-elytron-sasl-1.15.3.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform 1.15.3, org.wildfly.security.wildfly-elytron-sasl-1.15.3.Final-redhat-00001.jar
Red HatNone.object.map-1.0.1 as a component of Red Hat JBoss Enterprise Application Platform 1.0.1, None.object.map-1.0.1
Red HatNone.pretty-bytes-3.0.1 as a component of Red Hat JBoss Enterprise Application Platform None.pretty-bytes-3.0.1, 3.0.1
Red HatNone.path-root-0.1.1 as a component of Red Hat JBoss Enterprise Application Platform None.path-root-0.1.1, 0.1.1
Red Hatorg.apache.activemq.artemis-cli-2.16.0.redhat-00022.jar as a component of Red Hat JBoss Enterprise Application Platform 2.16.0, org.apache.activemq.artemis-cli-2.16.0.redhat-00022.jar
Red Hat@types.d3-timer-1.0.7 as a component of Red Hat JBoss Enterprise Application Platform @types.d3-timer-1.0.7, 1.0.7
Red Hatorg.picketbox.common-spi-5.0.3.Final-redhat-00007.pom as a component of Red Hat JBoss Enterprise Application Platform 5.0.3, org.picketbox.common-spi-5.0.3.Final-redhat-00007.pom
Red HatNone.redent-1.0.0 as a component of Red Hat JBoss Enterprise Application Platform None.redent-1.0.0, 1.0.0
Red Hatxerces.xercesImpl-2.12.0.SP03-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform *, 2.12.0
Red Hatorg.jboss.metadata.jboss-metadata-appclient-13.0.0.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform org.jboss.metadata.jboss-metadata-appclient-13.0.0.Final-redhat-00001.jar, 13.0.0
Red Hatorg.jboss.ws.cxf.jbossws-cxf-transports-undertow-5.4.2.Final-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform 5.4.2, *
Red HatNone.sprintf-js-1.0.3 as a component of Red Hat JBoss Enterprise Application Platform None.sprintf-js-1.0.3, 1.0.3
Red HatNone.rw-1.3.3 as a component of Red Hat JBoss Enterprise Application Platform 1.3.3, *
Red HatNone.escape-html-1.0.3 as a component of Red Hat JBoss Enterprise Application Platform *, 1.0.3
Red HatNone.object-visit-1.0.1 as a component of Red Hat JBoss Enterprise Application Platform 1.0.1, None.object-visit-1.0.1

…and 2017 more

Timeline

  • Jul 21, 2021 CVE Published
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 14, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›