A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource methods parameter value. The highest threat from this vulnerability is to data confidentiality.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Resteasy | Redhat | * | 4.6.0 (including) |
EAP 7.3.10 GA | RedHat | resteasy-jaxrs | * |
EAP 7.4.2 release | RedHat | * | |
Red Hat AMQ 7.9.0 | RedHat | resteasy-jaxrs | * |
Red Hat build of Quarkus 2.2.3 | RedHat | resteasy-core | * |
Red Hat EAP-XP 2 via EAP 7.3.x base | RedHat | resteasy-jaxrs | * |
Red Hat Integration Camel Quarkus 2 | RedHat | resteasy-core | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-apache-cxf-0:3.3.12-1.redhat_00001.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-ironjacamar-0:1.5.3-1.Final_redhat_00001.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-jakarta-el-0:3.0.3-3.redhat_00007.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-jboss-ejb-client-0:4.0.43-1.Final_redhat_00001.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-jboss-server-migration-0:1.7.2-10.Final_redhat_00011.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-jsoup-0:1.14.2-1.redhat_00002.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-resteasy-0:3.11.5-1.Final_redhat_00001.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-undertow-0:2.0.41-1.SP1_redhat_00001.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-wildfly-0:7.3.10-2.GA_redhat_00003.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-wildfly-elytron-0:1.10.15-1.Final_redhat_00001.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-wss4j-0:2.2.7-1.redhat_00001.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | RedHat | eap7-xml-security-0:2.1.7-1.redhat_00001.1.el6eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-apache-cxf-0:3.3.12-1.redhat_00001.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-ironjacamar-0:1.5.3-1.Final_redhat_00001.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-jakarta-el-0:3.0.3-3.redhat_00007.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-jboss-ejb-client-0:4.0.43-1.Final_redhat_00001.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-jboss-server-migration-0:1.7.2-10.Final_redhat_00011.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-jsoup-0:1.14.2-1.redhat_00002.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-resteasy-0:3.11.5-1.Final_redhat_00001.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-undertow-0:2.0.41-1.SP1_redhat_00001.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-wildfly-0:7.3.10-2.GA_redhat_00003.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-wildfly-elytron-0:1.10.15-1.Final_redhat_00001.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-wss4j-0:2.2.7-1.redhat_00001.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7 | RedHat | eap7-xml-security-0:2.1.7-1.redhat_00001.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-apache-cxf-0:3.3.12-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-ironjacamar-0:1.5.3-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-jakarta-el-0:3.0.3-3.redhat_00007.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-jboss-ejb-client-0:4.0.43-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-jboss-server-migration-0:1.7.2-10.Final_redhat_00011.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-jsoup-0:1.14.2-1.redhat_00002.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-resteasy-0:3.11.5-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-undertow-0:2.0.41-1.SP1_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-wildfly-0:7.3.10-2.GA_redhat_00003.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-wildfly-elytron-0:1.10.15-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-wss4j-0:2.2.7-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8 | RedHat | eap7-xml-security-0:2.1.7-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-resteasy-0:3.15.2-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | RedHat | eap7-resteasy-0:3.15.2-1.Final_redhat_00001.1.el7eap | * |
Red Hat Single Sign-On 7.4.10 | RedHat | resteasy-jaxrs | * |
Red Hat Single Sign-On 7.5 for RHEL 7 | RedHat | rh-sso7-keycloak-0:15.0.4-1.redhat_00001.1.el7sso | * |
Red Hat Single Sign-On 7.5 for RHEL 8 | RedHat | rh-sso7-keycloak-0:15.0.4-1.redhat_00001.1.el8sso | * |
Red Hat Support for Spring Boot 2.5.10 | RedHat | resteasy-jaxrs | * |
RHAF Camel-K 1.8 | RedHat | resteasy-core | * |
RHEL-8 based Middleware Containers | RedHat | rh-sso-7/sso75-openshift-rhel8:7.5-15 | * |
RHINT Service Registry 2.0.2 GA | RedHat | resteasy-core | * |
RHSSO 7.5.1 | RedHat | * | |
Resteasy | Ubuntu | devel | * |
Resteasy | Ubuntu | esm-apps/focal | * |
Resteasy | Ubuntu | esm-apps/jammy | * |
Resteasy | Ubuntu | esm-apps/noble | * |
Resteasy | Ubuntu | esm-apps/xenial | * |
Resteasy | Ubuntu | focal | * |
Resteasy | Ubuntu | groovy | * |
Resteasy | Ubuntu | hirsute | * |
Resteasy | Ubuntu | impish | * |
Resteasy | Ubuntu | jammy | * |
Resteasy | Ubuntu | kinetic | * |
Resteasy | Ubuntu | lunar | * |
Resteasy | Ubuntu | mantic | * |
Resteasy | Ubuntu | noble | * |
Resteasy | Ubuntu | oracular | * |
Resteasy | Ubuntu | plucky | * |
Resteasy | Ubuntu | trusty | * |
Resteasy | Ubuntu | upstream | * |
Resteasy | Ubuntu | xenial | * |
Resteasy3.0 | Ubuntu | bionic | * |
Resteasy3.0 | Ubuntu | devel | * |
Resteasy3.0 | Ubuntu | esm-apps/bionic | * |
Resteasy3.0 | Ubuntu | esm-apps/focal | * |
Resteasy3.0 | Ubuntu | esm-apps/jammy | * |
Resteasy3.0 | Ubuntu | esm-apps/noble | * |
Resteasy3.0 | Ubuntu | focal | * |
Resteasy3.0 | Ubuntu | groovy | * |
Resteasy3.0 | Ubuntu | hirsute | * |
Resteasy3.0 | Ubuntu | impish | * |
Resteasy3.0 | Ubuntu | jammy | * |
Resteasy3.0 | Ubuntu | kinetic | * |
Resteasy3.0 | Ubuntu | lunar | * |
Resteasy3.0 | Ubuntu | mantic | * |
Resteasy3.0 | Ubuntu | noble | * |
Resteasy3.0 | Ubuntu | oracular | * |
Resteasy3.0 | Ubuntu | plucky | * |
Resteasy3.0 | Ubuntu | trusty | * |
Resteasy3.0 | Ubuntu | upstream | * |