CVE-2020-1710: Red Hat JBoss Data Grid

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.

Affected products

  • Red Hat JBoss Data Grid: affected versions not specified; version 7.0.0 only
  • Red Hat JBoss Enterprise Application Platform: affected versions not specified; version 6.4.21 only; version 7.0.0 only; version 7.2.0 only; version 7.3.0 only
  • Red Hat Openshift Application Runtimes: affected versions not specified
  • Red Hat Single Sign-On: affected versions not specified

Published 2020-09-16. Last modified 2026-06-17.