GHSA-57q5-x8jf-g7h8
Dashboard / Vulnerabilities / GHSA-57q5-x8jf-g7h8
Summary: Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP
Details: Red Hat JBoss EAP version 3.0.7.Final until 3.0.25.Final, 3.5.0.CR1, and 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-7561, https://access.redhat.com/errata/RHSA-2018:0002, https://access.redhat.com/errata/RHSA-2018:0003, https://access.redhat.com/errata/RHSA-2018:0004, https://access.redhat.com/errata/RHSA-2018:0005, https://access.redhat.com/errata/RHSA-2018:0478, https://access.redhat.com/errata/RHSA-2018:0479, https://access.redhat.com/errata/RHSA-2018:0480, https://access.redhat.com/errata/RHSA-2018:0481, https://github.com/resteasy/Resteasy, https://issues.jboss.org/browse/RESTEASY-1704
Affected packages
Package
Name: org.jboss.resteasy:resteasy-jaxrs
Purl: pkg:maven/org.jboss.resteasy/resteasy-jaxrs
Affected ranges
Type: ECOSYSTEM
Events:
