CVE-2020-1695

Aliases:GHSA-63cq-ppq8-cw6g
Advisory lineage Upstream: 0 Downstream: 12
Modified
Published: 19 May 2020, 14:13
Last modified:04 Aug 2024, 06:46

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.0 (cve.org)
EPSS Score
0.37% LOW
0% probability -0.39%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 May 2020, 14:13
Published
Vulnerability first disclosed
04 Aug 2024, 06:46
Last Modified
Vulnerability information updated

Description

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 0.37% Percentile: 59%

Techniques & Countermeasures

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Affected Systems

  • fedoraprojectfedora

    32 | 33

  • org.jboss.resteasyresteasy-client

    ≥ 4.0.0, < 4.6.0 | ≥ 3.0.0, < 3.12.0

  • red hatresteasy

    all resteasy 3.x.x versions prior to 3.12.0.Final | all resteasy 4.x.x versions prior to 4.6.0.Final

  • redhatresteasy

    ≥ 3.0.0, < 3.12.0 | ≥ 4.0.0, < 4.6.0

References (7)