Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
{ "binaries": [ { "binary_name": "libresteasy3.0-java", "binary_version": "3.0.26-1~18.04.1~esm1" } ] }