Description
Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
Remediation
References
http://www.securityfocus.com/bid/100465
https://access.redhat.com/errata/RHSA-2018:0002
https://access.redhat.com/errata/RHSA-2018:0003
https://access.redhat.com/errata/RHSA-2018:0004
https://access.redhat.com/errata/RHSA-2018:0005
https://access.redhat.com/errata/RHSA-2018:0478
https://access.redhat.com/errata/RHSA-2018:0479
https://access.redhat.com/errata/RHSA-2018:0480
https://access.redhat.com/errata/RHSA-2018:0481
https://issues.jboss.org/browse/RESTEASY-1704
Related Vulnerabilities
CVE-2016-10688 Vulnerability in npm package haxe3
CVE-2019-10382 Vulnerability in maven package org.jenkins-ci.plugins:labmanager
CVE-2020-8929 Vulnerability in maven package com.google.crypto.tink:tink
CVE-2016-8745 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2020-7642 Vulnerability in maven package org.webjars.bower:lazysizes