{"id":"GHSA-57q5-x8jf-g7h8","summary":"Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP","details":"Red Hat JBoss EAP version 3.0.7.Final until 3.0.25.Final, 3.5.0.CR1, and 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.","aliases":["CVE-2017-7561"],"modified":"2025-01-15T15:26:01.418975Z","published":"2022-05-13T01:47:01Z","database_specific":{"cwe_ids":["CWE-444"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-07-01T11:43:57Z","nvd_published_at":"2017-09-13T17:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7561"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:0002"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:0003"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:0004"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:0005"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:0478"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:0479"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:0480"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:0481"},{"type":"PACKAGE","url":"https://github.com/resteasy/Resteasy"},{"type":"WEB","url":"https://issues.jboss.org/browse/RESTEASY-1704"}],"affected":[{"package":{"name":"org.jboss.resteasy:resteasy-jaxrs","ecosystem":"Maven","purl":"pkg:maven/org.jboss.resteasy/resteasy-jaxrs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.7.Final"},{"fixed":"3.0.25.Final"}]}],"versions":["3.0.10.Final","3.0.11.Final","3.0.12.Final","3.0.13.Final","3.0.14.Final","3.0.15.Final","3.0.16.Final","3.0.17.Final","3.0.18.Final","3.0.19.Final","3.0.20.Final","3.0.21.Final","3.0.22.Final","3.0.23.Final","3.0.24.Final","3.0.7.Final","3.0.8.Final","3.0.9.Final"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.0.24.Final","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-57q5-x8jf-g7h8/GHSA-57q5-x8jf-g7h8.json"}},{"package":{"name":"org.jboss.resteasy:resteasy-jaxrs","ecosystem":"Maven","purl":"pkg:maven/org.jboss.resteasy/resteasy-jaxrs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.4.Final"},{"fixed":"3.5.0.CR1"}]}],"versions":["3.1.4.Final"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-57q5-x8jf-g7h8/GHSA-57q5-x8jf-g7h8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}