Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-h84g-69h7-mw6v
  • Maven/com.mchange:mchange-commons-java
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets" yesterday
  • Fix available
  • Severity - 7.1 (High)
GHSA-fpmh-vx4h-xc33
  • Maven/org.openidentityplatform.openam:openam-core
OpenAM Insecure SSO Cookie Initialization yesterday
  • Fix available
  • Severity - 7.0 (High)
GHSA-p9jm-q85p-7mcp
  • Maven/io.netty:netty-codec-redis
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state 07 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-pmhh-3w7g-xqp8
  • Maven/org.jsoup:jsoup
jsoup: Cleaner may expose markup with custom raw-text elements 06 Aug
  • Fix available
  • Severity - 4.7 (Medium)
GHSA-pjp7-q6wp-97qx
  • Maven/org.geonetwork-opensource:geonetwork
core-geonetwork has an Open Redirect Bypass 31 Jul
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-93wv-jw9v-4972
  • Maven/io.netty:netty-codec-http2
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS) 31 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-88fw-v6x4-3f58
  • Maven/org.springframework.data:spring-data-commons
Spring Data: Unbounded property-path cache keyed by externally-supplied path string 31 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-hjcp-jmpx-g3qm
  • Maven/org.apache.httpcomponents.client5:httpclient5
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS 31 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-rwqx-fvqh-6wm4
  • Maven/io.opentelemetry.javaagent:opentelemetry-javaagent
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords 29 Jul
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-fq3f-m5qm-99f5
  • Maven/io.opentelemetry.javaagent:opentelemetry-javaagent
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion 29 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-qcxp-gm7m-4j5v
  • Maven/io.quarkus:quarkus-vertx-http
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities 29 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-7c26-995w-6f47
  • Maven/org.verapdf:parser
veraPDF Parser DoS via PostScript Type 1 Font Programs 29 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-jrmc-qg6p-94fp
  • Maven/org.verapdf:parser
veraPDF Parser DoS via PostScript CMap Streams 29 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-cg9x-g3gm-h5h6
  • Maven/org.verapdf:validation-model
  • Maven/org.verapdf:validation-model-jakarta
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs 29 Jul
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-3jh7-wm29-q568
  • Maven/org.verapdf:validation-model
  • Maven/org.verapdf:validation-model-jakarta
veraPDF Validation XXE via Rich Text 29 Jul
  • Fix available
  • Severity - 8.7 (High)
GHSA-36mm-w85j-3q2j
  • Maven/org.verapdf:validation-model
  • Maven/org.verapdf:validation-model-jakarta
veraPDF Validation XXE via XFA 29 Jul
  • Fix available
  • Severity - 8.7 (High)