CVE-2016-6345

MEDIUM6.5EPSS 0.08%

Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy

Published: 5/17/2022Modified: 4/28/2026
Also known as:DEBIAN-CVE-2016-6345

Description

RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (3)