SCA: security update for org.jboss.resteasy:resteasy-bom (GHSA-9699-gm7f-cmjv)

medium Tenable Cloud Security Plugin ID 413076

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows
an attacker to gain access to privileged information. The highest threat from this vulnerability is to
confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected. (CVE-2020-25724)

See Also

https://github.com/advisories/GHSA-9699-gm7f-cmjv

Plugin Details

Severity: Medium

ID: 413076

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2020-25724

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/8/2021

Vulnerability Publication Date: 5/26/2021

Reference Information

CVE: CVE-2020-25724

cwe: CWE-567