Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-7c5v-895v-w4q5
  • Maven/io.jooby:jooby-pac4j
jooby-pac4j: deserialization of untrusted data yesterday
  • Fix available
  • Severity - 8.8 (High)
GHSA-vq4p-pchp-6g6v
  • Maven/org.apache.camel:camel-undertow
Apache Camel Missing Header Out Filter Leads to Potential Bypass/Injection Vulnerability yesterday
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2c59-37c4-qrx5
  • Maven/org.apache.parquet:parquet-avro
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution yesterday
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-6jwp-4wvj-6597
  • Maven/org.apache.pinot:pinot
Apache Pinot Vulnerable to Authentication Bypass yesterday
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-3w85-5p9g-h334
  • Maven/org.apache.activemq:artemis-server
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type yesterday
  • Fix available
  • Severity - 2.3 (Low)
GHSA-hqqc-jr88-p6x2
  • Maven/io.netty.incubator:netty-incubator-codec-quic
Netty QUIC hash collision DoS attack yesterday
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-2m4q-2c6r-hmc3
  • Maven/org.noear:solon-view
Solon Vulnerable to Path Traversal 2 days ago
  • No fix available
  • Severity - 5.3 (Medium)
GHSA-2q39-w2hw-2pjm
  • Maven/org.infinispan:infinispan-query
Infinispan Potential Out of Memory Error via REST Compare API Buffer API 4 days ago
  • No fix available
  • Severity - 6.5 (Medium)
GHSA-29m8-wh9p-5wc4
  • Maven/org.apache.kylin:kylin
Apache Kylin Code Injection via JDBC Configuration Alteration 5 days ago
  • Fix available
  • Severity - 2.1 (Low)
GHSA-3v67-545x-ffc3
  • Maven/org.apache.kylin:kylin-common-server
Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint 5 days ago
  • Fix available
  • Severity - 2.1 (Low)
GHSA-5565-3c98-g6jc
  • Maven/org.wildfly.security:wildfly-elytron
  • Maven/org.wildfly.security:wildfly-elytron-http-oidc
WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack 25 Mar
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-2935-2wfm-hhpv
  • Maven/org.keycloak:keycloak-services
Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache 25 Mar
  • No fix available
  • Severity - 4.9 (Medium)
GHSA-v3vp-fg2v-g7q4
  • Maven/org.opendaylight.sfc:odl-sfc-openflow-renderer
  • Maven/org.opendaylight.sfc:odl-sfc-ovs
OpenDaylight SFC Denial of Service (DoS) 24 Mar
  • No fix available
  • Severity - 7.5 (High)
GHSA-x65v-g96x-c6gw
  • Maven/org.opendaylight.sfc:sfc-parent
OpenDaylight SFC Allows Unauthorized Privileged Execution via Crafted Request 24 Mar
  • No fix available
  • Severity - 9.8 (Critical)
GHSA-xp75-w7vq-5x6j
  • Maven/org.opendaylight.sfc:odl-sfc-ovs
  • Maven/org.opendaylight.sfc:odl-sfc-openflow-renderer
OpenDaylight SFC Insecure Shiro Cookie Configuration 24 Mar
  • No fix available
  • Severity - 8.1 (High)
GHSA-hh3m-g4qj-4835
  • Maven/org.springframework.security:spring-security-core
Spring Security Vulnerable to Authorization Bypass via Security Annotations 24 Mar
  • Fix available
  • Severity - 5.3 (Medium)