Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Mageia 7: MGASA-2021-0039 Moderate: Resteasy HTTP Injection Issue

mageia
Calendar Grey January 17, 2021
Dist Mageia Esm H88
Mageia 2021-0040 addresses a critical issue in wildfly; improper handling opens pathways for code execution attacks in user sessions.
A flaw was found in Resteasy, where an improper input validation results in returning an illegal header that integrates into the server's response

Summary

A flaw was found in Resteasy, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed (CVE-2020-1695).

References

- https://bugs.mageia.org/show_bug.cgi?id=27794

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/IJDMT443YZWCBS5NS76XZ7TL3GK7BXHL/

- https://www.cve.org/CVERecord?id=CVE-2020-1695

Resolution

SRPMS

- 7/core/resteasy-3.0.26-2.mga7

Publication date: 17 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0039.html
Type: security
CVE: CVE-2020-1695

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here