Impact
Jastow is vulnerable to a cross‑site scripting flaw (CWE‑79) that arises when unescaped characters in URLs are allowed by the embedded Undertow configuration. If an attacker injects crafted input into a URI, the server may reflect it without proper sanitization, allowing the victim’s browser to execute arbitrary JavaScript. The impact is client‑side script execution via reflected input.
Affected Systems
Red Hat JBoss Enterprise Application Platform versions 7, 8, 8.1 (including EL 8, EL 9, and EL 10 distributions) and the Red Hat Single Sign‑On 7 are affected. These are the products listed in the CNA vendor‑product entries and the matched CPEs.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5 indicating moderate severity. EPSS score of <1 % indicates a very low exploitation probability, and the flaw is not listed in the CISA KEV catalog, implying no publicly known attacks have been reported. The attack vector is inferred to be remote, web‑based, relying on an authenticated or unauthenticated client sending a specially crafted URL to the server. Successful exploitation requires the specific configuration where Undertow allows unescaped characters in the URL and Jastow’s escape‑error‑message setting is enabled.
OpenCVE Enrichment