Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
No PoCs from references.
- https://github.com/0ang3el/Unsafe-JAX-RS-Burp
- https://github.com/ARPSyndicate/cvemon