Apache

Brooklyn

3 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Published 13.09.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit a malicious web site to produce a link which, if clicked whilst a user is logged in to Brooklyn, would cause the server to execut...

Exploit
  • EPSS 0.46%
  • Published 13.09.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal data to a Java type. In the default configuration in Brooklyn before 0.10.0, SnakeYAML will allow un...

Exploit
  • EPSS 0.27%
  • Published 13.09.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the browser of another user authorized to access the first user's resources. This is due to improper esca...