Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-w4cm-gvhj-cgw6
  • Maven/org.typelevel:jawn-parser_2.12
  • Maven/org.typelevel:jawn-parser_2.13
  • Maven/org.typelevel:jawn-parser_3
Jawn: Quadratic parsing effort in AsyncParser 19 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-cc4v-rvgp-2pf3
  • Maven/org.typelevel:jawn-parser_2.12
  • Maven/org.typelevel:jawn-parser_2.13
  • Maven/org.typelevel:jawn-parser_3
Jawn: Uncontrolled nesting depth in JSON parser 19 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-ph9c-7hw9-vhhw
  • Maven/org.jline:jline-builtins
JLine: ReDoS in Nano Editor Regex Search Mode 22 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-r2xf-8xr9-62gw
  • Maven/org.jline:jline-builtins
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping 22 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-5q95-hrpc-m3w3
  • Maven/org.jline:jline-reader
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable 22 hours ago
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-5f42-97gr-vfhq
  • Maven/io.moquette:moquette-broker
Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug yesterday
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-m9c2-85gv-8xr5
  • Maven/org.graylog2:graylog2-server
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards yesterday
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-7952-gx68-cjqr
  • Maven/net.sf.mpxj:mpxj
  • NuGet/MPXJ.Net
  • NuGet/net.sf.mpxj
  • NuGet/net.sf.mpxj-for-csharp
  • NuGet/net.sf.mpxj-for-vb
  • ... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers yesterday
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
  • Maven/net.sf.mpxj:mpxj
  • NuGet/MPXJ.Net
  • NuGet/net.sf.mpxj
  • NuGet/net.sf.mpxj-for-csharp
  • NuGet/net.sf.mpxj-for-vb
  • ... 2 more
MPXJ: XXE Vulnerability in MerlinReader yesterday
  • Fix available
  • Severity - 7.5 (High)
GHSA-9jjc-fw8x-fmwx
  • Maven/io.moquette:moquette-broker
io.moquette:moquette-broker has a Missing Authorization issue 5 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-26vp-8gxg-v4pg
  • Maven/org.xwiki.rendering:xwiki-rendering-xml
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue 6 days ago
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-m6c8-jcw2-5r25
  • Maven/org.opencastproject:opencast-engage-paella-player-7
  • npm/paella-core
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text 6 days ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-gq9c-wmrm-5hvr
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.r5
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service 6 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-3w98-rrpr-fprr
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.r5
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation
  • Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service 6 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-f8m2-889x-vw4x
  • Maven/org.asynchttpclient:async-http-client
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target 6 days ago
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-xr57-gcx8-52hf
  • Maven/org.asynchttpclient:async-http-client
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request 6 days ago
  • Fix available
  • Severity - 5.9 (Medium)