RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.jboss.resteasy:resteasy-client(Maven) | 0 | 3.0.20.Final | N/A |
| org.jboss.resteasy:resteasy-client(Maven) | 3.1.0.Beta1 | 3.1.0.CR1 | N/A |
CVSS Metrics