ubuntu · CVE-2016-6348

Quick triage

Priority: medium Published: 2017-04-12 22:59:00 UTC Updated: 2025-09-09 14:00:50 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-6348 medium priority: Ubuntu including 2 source packages (resteasy, resteasy3.0), 28 status rows across 22 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, precise, trusty, upstream, xenial, yakkety, zesty): ignored 11, not-affected 10, DNE 4, released 3.

Description:

JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.

cvelogic Threat Intelligence