CVE-2023-4066
- EPSS 0.04%
- Published 27.09.2023 21:15:10
- Last modified 21.11.2024 08:34:20
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
CVE-2023-4065
- EPSS 0.04%
- Published 27.09.2023 15:19:39
- Last modified 21.11.2024 08:34:19
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their perm...
CVE-2023-4853
- EPSS 0.35%
- Published 20.09.2023 10:15:14
- Last modified 21.11.2024 08:36:06
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security ...
CVE-2018-1304
- EPSS 1.79%
- Published 28.02.2018 20:29:00
- Last modified 21.11.2024 03:59:35
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definiti...
CVE-2017-7957
- EPSS 2.95%
- Published 29.04.2017 19:59:00
- Last modified 23.05.2025 17:54:30
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>...
CVE-2016-3674
- EPSS 2.35%
- Published 17.05.2016 14:08:03
- Last modified 23.05.2025 17:54:18
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbi...