Description
JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1372129
Related Vulnerabilities
CVE-2021-20293 Vulnerability in maven package org.jboss.resteasy:resteasy-core
CVE-2020-21122 Vulnerability in maven package com.bstek.ureport:ureport2-console
CVE-2023-29206 Vulnerability in maven package org.xwiki.platform:xwiki-platform-skin-skinx
CVE-2015-1832 Vulnerability in maven package org.apache.derby:derby