Untriaged
Permalink
CVE-2026-89058
7.4 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
Activity log
- Created suggestion
Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality.
References
Affected products
RESTEasy
- <7.0.5.Final
- <6.2.19.Final
pki-core
candlepin
dogtag-pki
redhat-pki
resteasy-core
resteasy-jaxrs
pki-core:10.6/pki-core
jackson-jaxrs-providers
redhat-pki:10/redhat-pki
rhbk/keycloak-rhel9-operator
jboss-eap-7/eap74-els-openjdk8-openshift-rhel8
jboss-eap-7/eap74-els-openjdk11-openshift-rhel8
jboss-eap-7/eap74-els-openjdk17-openshift-rhel8
Matching in nixpkgs
pkgs.python313Packages.dogtag-pki
Enterprise-class Certificate Authority
pkgs.python314Packages.dogtag-pki
Enterprise-class Certificate Authority
Package maintainers
-
@s1341 Shmarya Rubenstein <s1341@shmarya.net>