Bug 27750 - resteasy: new security issue CVE-2020-25633)
Summary: resteasy: new security issue CVE-2020-25633)
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: David GEIGER
QA Contact: Sec team
URL: https://access.redhat.com/security/cv...
Whiteboard:
Keywords:
Depends on: 27794
Blocks: 24817
  Show dependency treegraph
 
Reported: 2020-12-05 14:37 CET by David Walser
Modified: 2026-01-12 10:56 CET (History)
4 users (show)

See Also:
Source RPM: resteasy-3.0.26-1.mga8.src.rpm
CVE: CVE-2020-25633
Status comment:
marja11: affects_mga9+


Attachments

Description David Walser 2020-12-05 14:37:23 CET
https://bugzilla.redhat.com/show_bug.cgi?id=1879042

There doesn't seem to be a fix available yet.
David Walser 2020-12-05 14:37:52 CET

CC: (none) => zombie_ryushu
Whiteboard: (none) => MGA7TOO
Blocks: (none) => 24817

David Walser 2020-12-05 14:38:05 CET

Blocks: 24817 => (none)

David Walser 2020-12-05 14:38:20 CET

Blocks: (none) => 24817

David Walser 2020-12-09 23:55:52 CET

Depends on: (none) => 27794

David Walser 2020-12-27 22:32:47 CET

Status comment: (none) => No fix available as of end of 2020

David Walser 2020-12-28 17:10:13 CET

Whiteboard: MGA7TOO => MGA8TOO, MGA7TOO

Comment 1 Zombie Ryushu 2021-02-20 09:41:21 CET
A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the RESTEasy client call. The highest threat from this vulnerability is to data confidentiality.

CVE: (none) => CVE-2020-25633

Comment 2 David Walser 2021-07-01 18:46:26 CEST
Removing Mageia 7 from whiteboard due to EOL:
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Whiteboard: MGA8TOO, MGA7TOO => MGA8TOO

Comment 3 David GEIGER 2024-06-15 08:33:47 CEST
Removing Mageia 8 from whiteboard due to EOL.

Whiteboard: MGA8TOO => MGA9TOO
CC: (none) => geiger.david68210

Comment 4 Marja Van Waes 2025-12-31 14:04:30 CET
Adding the flag: affects_mga9 +
to all bugs with MGA9TOO on the whiteboard, without removing MGA9TOO (for now).

Flags: (none) => affects_mga9+

Comment 5 Marja Van Waes 2026-01-11 21:23:12 CET
Paging through https://access.redhat.com/security/cve/cve-2020-25633#additional-info :

It seems they fixed it for many of their products.

However, I find nothing at https://resteasy.jboss.org/ 

But there is this (still opem) issue about that CVE: 

https://github.com/jakartaee/rest/issues/917

Do we still need the four pki-resteasy packages at all?

CC: (none) => marja11
URL: (none) => https://access.redhat.com/security/cve/cve-2020-25633

Comment 6 Marja Van Waes 2026-01-11 21:31:48 CET
(In reply to Marja Van Waes from comment #5)
> Paging through
> https://access.redhat.com/security/cve/cve-2020-25633#additional-info :
> 
> It seems they fixed it for many of their products.
> 
> However, I find nothing at https://resteasy.jboss.org/ 
> 
> But there is this (still opem) issue about that CVE: 
> 
> https://github.com/jakartaee/rest/issues/917
> 
> Do we still need the four pki-resteasy packages at all?

Let's just obsolete them. If you don't agree, then stop this report from blocking bug 32127

Summary: resteasy new security issue CVE-2020-25633 => Obsolete resteasy (was: new security issue CVE-2020-25633)
Blocks: (none) => 32127

Comment 7 David Walser 2026-01-12 00:06:47 CET
Agreed.  IIRC, Fedora removed most of these old Java library packages, as they were no longer being maintained.  We should be doing the same.
Comment 8 r howard 2026-01-12 01:25:28 CET
It seems sponsorship of RestEasy was taken over by Commonhaus.org and the general information page is at https://resteasy.dev/ and the source moved to https://github.com/resteasy/resteasy some time ago and is still being developed. CVE-2020-25633 was fixed a long time ago. See https://issues.redhat.com/browse/RESTEASY-2721

CC: (none) => rihoward1

Comment 9 Marja Van Waes 2026-01-12 10:56:39 CET
(In reply to r howard from comment #8)
> It seems sponsorship of RestEasy was taken over by Commonhaus.org and the
> general information page is at https://resteasy.dev/ and the source moved to
> https://github.com/resteasy/resteasy some time ago and is still being
> developed. CVE-2020-25633 was fixed a long time ago. See
> https://issues.redhat.com/browse/RESTEASY-2721

Thanks for the feedback.

Assigning to daviddavid, because he told us not to obsolete resteasy.

(also removing the whiteboard string, since it was replaced by a flag)

Status comment: No fix available as of end of 2020 => (none)
Assignee: java => geiger.david68210
Blocks: 32127 => (none)
Summary: Obsolete resteasy (was: new security issue CVE-2020-25633) => resteasy: new security issue CVE-2020-25633)
Whiteboard: MGA9TOO => (none)


Note You need to log in before you can comment on or make changes to this bug.