CVE-2020-10705
- EPSS 0.38%
- Veröffentlicht 10.06.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:53
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.
CVE-2020-10719
- EPSS 0.17%
- Veröffentlicht 26.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:55
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
CVE-2020-1714
- EPSS 2.15%
- Veröffentlicht 13.05.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:13
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privi...
CVE-2020-1718
- EPSS 0.37%
- Veröffentlicht 12.05.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:13
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.
CVE-2020-1724
- EPSS 0.23%
- Veröffentlicht 11.05.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:14
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
CVE-2020-1732
- EPSS 0.13%
- Veröffentlicht 04.05.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:15
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being han...
CVE-2020-1757
- EPSS 0.46%
- Veröffentlicht 21.04.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:19
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the ...
CVE-2019-14887
- EPSS 0.18%
- Veröffentlicht 16.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:27:36
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version...
CVE-2019-10174
- EPSS 1.04%
- Veröffentlicht 25.11.2019 11:15:10
- Zuletzt bearbeitet 21.11.2024 04:18:34
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to in...
CVE-2019-10219
- EPSS 1.67%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 07.07.2025 14:15:21
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.