Description
JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1372129
Related Vulnerabilities
CVE-2016-3092 Vulnerability in maven package commons-fileupload:commons-fileupload
CVE-2022-38900 Vulnerability in npm package decode-uri-component
CVE-2022-39353 Vulnerability in npm package xmldom
CVE-2021-3807 Vulnerability in npm package ansi-regex
CVE-2022-43670 Vulnerability in maven package org.apache.sling:org.apache.sling.cms