redhat resteasy CVE-2020-25724 in Red Hat and Quarkus Products
Published on May 26, 2021

product logo product logo
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.

NVD

Weakness Type

Unsynchronized Access to Shared Data in a Multithreaded Context

The product does not properly synchronize shared data, such as static variables across threads, which can lead to undefined behavior and unpredictable data changes.


Products Associated with CVE-2020-25724

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-25724 are published in these products:

 
 

Exploit Probability

EPSS
0.13%
Percentile
32.89%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.