Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
>= 3.0.7.Final, <= 3.0.24.Final
= 3.1.4.Final
Patched versions
3.0.25.Final
3.5.0.CR1
Description
Published by the National Vulnerability Database
Sep 13, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 1, 2022
Last updated
Jan 27, 2023
Red Hat JBoss EAP version 3.0.7.Final until 3.0.25.Final, 3.5.0.CR1, and 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
References