CVE-2020-25724: Quarkus

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.

Affected products

  • Quarkus Quarkus: before 1.11.2 (fixed in 1.11.2)
  • Red Hat Resteasy: before 2.0.0 (fixed in 2.0.0); version 2.0.0 only

Published 2021-05-26. Last modified 2026-06-17.