Red Hat Bugzilla – Bug 1372129
CVE-2016-6348 RESTEasy: Use of JacksonJsonpInterceptor in RESTEasy can lead to Cross Site Script Inclusion attack
Last modified: 2018-06-29 18:14:16 EDT
It was found that in some configurations the JacksonJsonpInterceptor is activated by default in RESTEasy. An attacker could use this flaw to launch a Cross Site Scripting Inclusion attack.
Acknowledgments: Name: Mikhail Egorov (Odin)
Created resteasy tracking bugs for this issue: Affects: fedora-all [bug 1372130]
Created resteasy tracking bugs for this issue: Affects: fedora-all [bug 1471279]
Created resteasy tracking bugs for this issue: Affects: fedora-all [bug 1481780]