VYPR
Medium severity6.5NVD Advisory· Published Sep 7, 2016· Updated May 6, 2026

CVE-2016-6345

CVE-2016-6345

Description

RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jboss.resteasy:resteasy-clientMaven
< 3.0.20.Final3.0.20.Final
org.jboss.resteasy:resteasy-clientMaven
>= 3.1.0.Beta1, < 3.1.0.CR13.1.0.CR1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.