Sensitive information sent insecurely In org.jboss.resteasy:resteasy-client
Description
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 3.0.20.final, 3.1.0.cr1 | ||
debian 13 | 3.0.26-1 | ||
debian 12 | 3.0.26-1 | ||
debian 14 | 3.0.26-1 | ||
debian 11 | 3.0.26-1 | ||
rpm rhel7 | - | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1.