CVE-2022-22968
- EPSS 22.75%
- Published 14.04.2022 21:15:08
- Last modified 21.11.2024 06:47:42
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and...
CVE-2020-36518
- EPSS 0.6%
- Published 11.03.2022 07:15:07
- Last modified 27.08.2025 21:15:36
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
CVE-2021-42550
- EPSS 4.29%
- Published 16.12.2021 19:15:08
- Last modified 21.11.2024 06:27:47
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
CVE-2021-22096
- EPSS 0.22%
- Published 28.10.2021 16:15:07
- Last modified 21.11.2024 05:49:31
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
CVE-2021-34429
- EPSS 93.8%
- Published 15.07.2021 17:15:08
- Last modified 21.11.2024 06:10:23
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerabilit...
CVE-2021-34428
- EPSS 0.51%
- Published 22.06.2021 15:15:16
- Last modified 21.11.2024 06:10:23
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and mul...
CVE-2021-28169
- EPSS 92.42%
- Published 09.06.2021 02:15:06
- Last modified 21.11.2024 05:59:14
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml...
CVE-2020-27223
- EPSS 33.82%
- Published 26.02.2021 22:15:19
- Last modified 20.08.2025 10:15:27
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) ...
CVE-2021-23901
- EPSS 1.07%
- Published 25.01.2021 10:16:33
- Last modified 21.11.2024 05:52:01
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to int...
CVE-2021-23926
- EPSS 0.32%
- Published 14.01.2021 15:15:13
- Last modified 21.11.2024 05:52:03
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.