Bug 27750 - resteasy new security issue CVE-2020-25633
Summary: resteasy new security issue CVE-2020-25633
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Java Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on: 27794
Blocks: 24817
  Show dependency treegraph
 
Reported: 2020-12-05 14:37 CET by David Walser
Modified: 2024-06-15 08:33 CEST (History)
2 users (show)

See Also:
Source RPM: resteasy-3.0.26-1.mga8.src.rpm
CVE: CVE-2020-25633
Status comment: No fix available as of end of 2020


Attachments

Description David Walser 2020-12-05 14:37:23 CET
https://bugzilla.redhat.com/show_bug.cgi?id=1879042

There doesn't seem to be a fix available yet.
David Walser 2020-12-05 14:37:52 CET

CC: (none) => zombie_ryushu
Whiteboard: (none) => MGA7TOO
Blocks: (none) => 24817

David Walser 2020-12-05 14:38:05 CET

Blocks: 24817 => (none)

David Walser 2020-12-05 14:38:20 CET

Blocks: (none) => 24817

David Walser 2020-12-09 23:55:52 CET

Depends on: (none) => 27794

David Walser 2020-12-27 22:32:47 CET

Status comment: (none) => No fix available as of end of 2020

David Walser 2020-12-28 17:10:13 CET

Whiteboard: MGA7TOO => MGA8TOO, MGA7TOO

Comment 1 Zombie Ryushu 2021-02-20 09:41:21 CET
A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the RESTEasy client call. The highest threat from this vulnerability is to data confidentiality.

CVE: (none) => CVE-2020-25633

Comment 2 David Walser 2021-07-01 18:46:26 CEST
Removing Mageia 7 from whiteboard due to EOL:
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Whiteboard: MGA8TOO, MGA7TOO => MGA8TOO

Comment 3 David GEIGER 2024-06-15 08:33:47 CEST
Removing Mageia 8 from whiteboard due to EOL.

Whiteboard: MGA8TOO => MGA9TOO
CC: (none) => geiger.david68210


Note You need to log in before you can comment on or make changes to this bug.