Description
JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1372129
Related Vulnerabilities
CVE-2014-6393 Vulnerability in npm package express
CVE-2020-24922 Vulnerability in maven package com.xuxueli:xxl-job-admin
CVE-2023-40573 Vulnerability in maven package org.xwiki.platform:xwiki-platform-scheduler-api
CVE-2017-18214 Vulnerability in maven package org.webjars.bowergithub.moment:moment
CVE-2018-25031 Vulnerability in maven package com.microfocus.webjars:swagger-ui-dist