REDHAT-BUG-2413071: XSS
Published Nov 6, 2025
·Updated
A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.
Affected Software
2 affected components
Jastow
Undertow
Event History
Nov 6, 2025
Data Sourced
via Red Hat·11:17 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2413071?
The severity of REDHAT-BUG-2413071 is medium with a score of 4.
2
What type of vulnerability is identified in REDHAT-BUG-2413071?
REDHAT-BUG-2413071 identifies a Cross-Site Scripting (XSS) vulnerability.
3
How do I fix REDHAT-BUG-2413071?
To fix REDHAT-BUG-2413071, ensure that the configuration does not allow unescaped characters in the URL when using Jastow with Undertow.
4
Which software is affected by REDHAT-BUG-2413071?
The software affected by REDHAT-BUG-2413071 includes Jastow and Undertow.
5
What impact does REDHAT-BUG-2413071 have on security?
REDHAT-BUG-2413071 can allow attackers to exploit improper input handling through Cross-Site Scripting (XSS).