CVE-2016-6348
MediumAdvisory
Published 17 May 2022In the index since 8 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.1
- base score, highest
- EPSS
- 0.016
- 74th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2
- of 17,781 indexed, latest versions
- Container images
- 15
- deployed by those charts
- Fix available
- 1 of 1
- affected package
JacksonJsonpInterceptor susceptible to cross-site script inclusion (XSSI) attack
Carried by container images the latest versions of 2 of 17,781 indexed charts deploy, on 15 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| resteasy-clientmaven | 3.0.8.Final, 3.0.9.Final | 3.0.20.Final | 15 |
- OSV records
- GHSA-9xfc-j5mf-9w5p
Charts affected
2 by stars
Container images carrying it
15 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| craigwillis/ | ae317d7e4724 | resteasy-client | 3.0.20.Final | 1 |
| ncsa/ | af6649d59150 | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | c44b22eb58bb | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | 438d82cdbdb5 | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | 48c852c1204b | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | 072cf5bc6f99 | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | f746049515c1 | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | f350da56dd55 | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | 317dd9e56922 | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | d244ea8c32ac | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | 2ba4af461d51 | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | 30ee96508c0b | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | 1d9cebe3022b | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | f889fe30e2c7 | resteasy-client | 3.0.20.Final | 1 |
| ncsapolyglot/ | 97a8c01c076e | resteasy-client | 3.0.20.Final | 1 |