CVE-2020-1695

HIGH7.5EPSS 0.37%

Improper Input Validation in RESTEasy

發布日:2022/5/24修改日:2024/2/21
也稱為:GHSA-63cq-ppq8-cw6gDEBIAN-CVE-2020-1695

描述

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

參考連結(6)