Impact
The flaw in RESTEasy’s CorsFilter causes the filter to echo the Origin header from a request back into the Access‑Control‑Allow‑Origin response when the filter is configured to accept all origins ("*"). Because the response also includes Access‑Control‑Allow‑Credentials: true, a malicious website can send credential‑enabled requests and read the authenticated responses of any user whose browser has a session with the target service, violating confidentiality. This is a classic example of a user‑controlled value being reflected in an HTTP response (CWE‑942 and CWE‑346).
Affected Systems
This vulnerability affects a broad range of Red Hat products that embed or depend on the RESTEasy library, including Red Hat Build of Keycloak, Red Hat Certificate System 10 and 11, Red Hat Enterprise Linux 8, 9 and 10, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Satellite 6, Red Hat Single Sign‑On 7, the Red Hat build of Apache Camel 4 for Quarkus 3, the Red Hat build of Apicurio Registry 3, the Red Hat build of Debezium 3, and the Red Hat build of Quarkus 3. The vulnerability exists wherever the affected version of RESTEasy is deployed in these environments.
Risk and Exploitability
The CVSS score of 7.4 places the flaw in the high‑severity range, while the EPSS score of less than 1% indicates that exploitation is currently uncommon. It is not listed in CISA’s KEV catalog. The most likely attack vector is a web‑based exploit, where an attacker lures a user to a malicious site that makes cross‑origin requests to the vulnerable API. Because the flaw only requires client‑side manipulation of the Origin header and the use of cookies or other credentials, an attacker can achieve credential‑based data exfiltration without needing privileged access to the target system. This weakness is represented by reflexive use of user‑controlled input in the HTTP response (CWE‑942 and CWE‑346).
OpenCVE Enrichment