Medium [CVE-2025-12799] Jastow Cross-Site Scripting attack due to unsanitized URI
This medium-severity Red Hat Linux advisory covers CVE-2025-12799 affecting Red Hat Enterprise Linux 1.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Jastow Cross-Site Scripting attack due to unsanitized URI. Red Hat rates this moderate (CVSS 6.5).
Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:36343 with package eap8-elytron-web-0:4.1.2-1.Final_redhat_00001.1.el10eap, eap8-jboss-ejb-client-0:5.0.8-1.Final_redhat_00001.1.el10eap, eap8-jandex-0:3.2.7-1.redhat_00001.1.el10eap, eap8-javaee-security-soteria-0:3.0.3-2.redhat_00001.1.el10eap.
Affected product named by the advisory: Red Hat Enterprise Linux 1.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
- eap8-elytron-web-0:4.1.2-1.Final_redhat_00001.1.el10eap
- eap8-jboss-ejb-client-0:5.0.8-1.Final_redhat_00001.1.el10eap
- eap8-jandex-0:3.2.7-1.redhat_00001.1.el10eap
- eap8-javaee-security-soteria-0:3.0.3-2.redhat_00001.1.el10eap
- eap8-jboss-dmr-0:1.7.0-2.Final_redhat_00001.1.el10eap
- eap8-fge-btf-0:1.2.0-4.redhat_00007.1.el10eap
- eap8-joda-time-0:2.12.7-1.redhat_00002.1.el10eap
- eap8-jakarta-resource-api-0:2.1.0-2.redhat_00001.1.el10eap
- eap8-jbossws-jaxws-undertow-httpspi-0:2.0.0-1.Final_redhat_00001.1.el10eap
- eap8-jackson-coreutils-0:1.8.0-3.redhat_00002.1.el10eap
- eap8-jgroups-aws-0:3.0.1-1.Final_redhat_00001.1.el10eap
- eap8-netty-0:4.1.132-1.Final_redhat_00001.1.el10eap
- eap8-parsson-0:1.1.7-3.redhat_00003.1.el10eap
- eap8-wildfly-0:8.1.7-4.GA_redhat_00003.1.el10eap
- eap8-netty-transport-native-epoll-0:4.1.132-1.Final_redhat_00001.1.el10eap
- eap8-aesh-readline-0:2.4.0-1.redhat_00002.1.el10eap
- eap8-hal-console-0:3.7.19-1.Final_redhat_00001.1.el10eap
- eap8-woodstox-core-0:7.0.0-1.redhat_00002.1.el10eap
- eap8-jboss-logging-0:3.6.2-1.Final_redhat_00001.1.el10eap
- eap8-protostream-0:5.0.14-2.Final_redhat_00002.1.el10eap
- RHSA-2026:36343
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Mitigation checklist
- It is possible to contruct successful attack vector if and only if customer or client is using embedded Undertow and Jastow together in their application and the following conditions are met: * Undertow was configured with UndertowOptions.ALLOW_UNESCAPED_CHARACTERS_IN_URL set to 'true' value * DeploymentInfo configured with setEscapeErrorMessage(true) method was passed to Undertow's Servlet Container instance
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.