Quarkus

Quarkus

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 19.10.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:14:42

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an...

  • EPSS 0.95%
  • Veröffentlicht 22.09.2021 09:15:07
  • Zuletzt bearbeitet 21.11.2024 06:16:30

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0....

  • EPSS 0.59%
  • Veröffentlicht 18.08.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:15:46

jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the par...

  • EPSS 0.27%
  • Veröffentlicht 05.08.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 06:22:03

A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 26.05.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 05:59:14

In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.

  • EPSS 0.13%
  • Veröffentlicht 26.05.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 05:18:35

A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions ...

Exploit
  • EPSS 45.48%
  • Veröffentlicht 23.04.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 05:56:01

Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves int...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 13.04.2021 20:15:21
  • Zuletzt bearbeitet 21.11.2024 06:01:04

In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation ...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 13.04.2021 20:15:21
  • Zuletzt bearbeitet 21.11.2024 06:01:04

In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositor...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 12.04.2021 22:15:13
  • Zuletzt bearbeitet 21.11.2024 06:01:04

In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files acce...