VDB
RHSA-2021:2858
RHSA-2021:2858
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A flaw was found in the RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. This flaw allows client users to obtain the server's potentially sensitive information when the server receives the WebApplicationException from the RESTEasy client call. The highest threat from this vulnerability is to confidentiality.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | org.wildfly.security.wildfly-elytron-json-util-1.15.3.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | 1.15.3, * |
| Red Hat | None.promise-7.3.1 as a component of Red Hat JBoss Enterprise Application Platform | *, 7.3.1 |
| Red Hat | None.unist-util-find-all-after-1.0.4 as a component of Red Hat JBoss Enterprise Application Platform | 1.0.4, None.unist-util-find-all-after-1.0.4 |
| Red Hat | None.estraverse-4.1.0 as a component of Red Hat JBoss Enterprise Application Platform | None.estraverse-4.1.0, 4.1.0 |
| Red Hat | com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.12.1.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.12.1.redhat-00001.pom, 2.12.1 |
| Red Hat | org.wildfly.security.wildfly-elytron-sasl-1.15.3.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | 1.15.3, org.wildfly.security.wildfly-elytron-sasl-1.15.3.Final-redhat-00001.jar |
| Red Hat | None.object.map-1.0.1 as a component of Red Hat JBoss Enterprise Application Platform | 1.0.1, None.object.map-1.0.1 |
| Red Hat | None.pretty-bytes-3.0.1 as a component of Red Hat JBoss Enterprise Application Platform | None.pretty-bytes-3.0.1, 3.0.1 |
| Red Hat | None.path-root-0.1.1 as a component of Red Hat JBoss Enterprise Application Platform | None.path-root-0.1.1, 0.1.1 |
| Red Hat | org.apache.activemq.artemis-cli-2.16.0.redhat-00022.jar as a component of Red Hat JBoss Enterprise Application Platform | 2.16.0, org.apache.activemq.artemis-cli-2.16.0.redhat-00022.jar |
| Red Hat | @types.d3-timer-1.0.7 as a component of Red Hat JBoss Enterprise Application Platform | @types.d3-timer-1.0.7, 1.0.7 |
| Red Hat | org.picketbox.common-spi-5.0.3.Final-redhat-00007.pom as a component of Red Hat JBoss Enterprise Application Platform | 5.0.3, org.picketbox.common-spi-5.0.3.Final-redhat-00007.pom |
| Red Hat | None.redent-1.0.0 as a component of Red Hat JBoss Enterprise Application Platform | None.redent-1.0.0, 1.0.0 |
| Red Hat | xerces.xercesImpl-2.12.0.SP03-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | *, 2.12.0 |
| Red Hat | org.jboss.metadata.jboss-metadata-appclient-13.0.0.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | org.jboss.metadata.jboss-metadata-appclient-13.0.0.Final-redhat-00001.jar, 13.0.0 |
| Red Hat | org.jboss.ws.cxf.jbossws-cxf-transports-undertow-5.4.2.Final-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | 5.4.2, * |
| Red Hat | None.sprintf-js-1.0.3 as a component of Red Hat JBoss Enterprise Application Platform | None.sprintf-js-1.0.3, 1.0.3 |
| Red Hat | None.rw-1.3.3 as a component of Red Hat JBoss Enterprise Application Platform | 1.3.3, * |
| Red Hat | None.escape-html-1.0.3 as a component of Red Hat JBoss Enterprise Application Platform | *, 1.0.3 |
| Red Hat | None.object-visit-1.0.1 as a component of Red Hat JBoss Enterprise Application Platform | 1.0.1, None.object-visit-1.0.1 |
…and 2017 more
Timeline
- Jul 21, 2021 CVE Published
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
References
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4 advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1879042 issue
- https://issues.redhat.com/browse/JBEAP-21120 advisory
- https://access.redhat.com/errata/RHSA-2021:2858 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=7.4 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2858.json advisory
- https://access.redhat.com/security/cve/CVE-2020-25633 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-25633 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25633 advisory