Information Exposure Affecting org.jboss.seam:jboss-seam-remoting package, versions [0,2.3.2.Final-redhat-2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (50th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJBOSSSEAM-483093
  • published10 Oct 2019
  • disclosed22 Jan 2014
  • creditUnknown

Introduced: 22 Jan 2014

CVE-2013-6448  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade org.jboss.seam:jboss-seam-remoting to version 2.3.2.Final-redhat-2 or higher.

Overview

org.jboss.seam:jboss-seam-remoting is a Seam Remoting library for JBoss.

Affected versions of this package are vulnerable to Information Exposure. It was found that the InterfaceGenerator handler in JBoss Seam Remoting will expose details of all classes and methods on the server's classpath, not just methods with the org.jboss.seam.annotations.remoting.WebRemote annotation. A remote attacker could use this flaw to determine which classes are deployed on the JBoss server.

CVSS Base Scores

version 3.1