{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3azohocorpmanageengine_adaudit_plus/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:resteasy:*:*:*:*:*:*:*:*","cpe:2.3:a:zohocorp:manageengine_adaudit_plus:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2024-5556"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Resteasy"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","information-disclosure","linux"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA vulnerability has been identified in the Resteasy component included within Red Hat Enterprise Linux (RHEL). This security flaw, tracked as CVE-2024-5556, permits a remote and unauthenticated attacker to exploit improper request handling, potentially leading to the disclosure of sensitive system or application information. The vulnerability affects the way Resteasy processes specific HTTP requests, allowing unauthorized access to data that should otherwise be protected. This risk is particularly relevant for organizations hosting Java-based web services or applications on RHEL that utilize the Resteasy framework. Defensive teams should prioritize assessing the exposure of applications utilizing this component and monitor for unusual request patterns aimed at the Resteasy endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthorized party to gain access to sensitive information, which could facilitate further reconnaissance or compromise the confidentiality of the affected web service. This impacts any enterprise infrastructure relying on Red Hat Enterprise Linux hosting Resteasy-based applications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReview RHEL security advisories for the specific patch version of Resteasy addressing CVE-2024-5556.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for high volumes of malformed or unexpected HTTP requests targeting application endpoints known to utilize Resteasy.\u003c/li\u003e\n\u003cli\u003eApply the latest security updates provided by Red Hat to all affected RHEL instances.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:15:06Z","date_published":"2026-10-08T19:15:06Z","id":"https://feed.craftedsignal.io/briefs/2026-10-resteasy-info-disclosure/","summary":"A vulnerability in the Resteasy component of Red Hat Enterprise Linux allows a remote, unauthenticated attacker to disclose sensitive information.","title":"Information Disclosure Vulnerability in Red Hat Enterprise Linux Resteasy","url":"https://feed.craftedsignal.io/briefs/2026-10-resteasy-info-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:zohocorp:manageengine_adaudit_plus:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}