CVE-2023-48362
- EPSS 0.18%
- Veröffentlicht 24.07.2024 08:15:02
- Zuletzt bearbeitet 21.11.2024 08:31:34
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.
CVE-2019-14439
- EPSS 9.41%
- Veröffentlicht 30.07.2019 11:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:44
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logbac...
CVE-2019-0201
- EPSS 0.29%
- Veröffentlicht 23.05.2019 14:29:07
- Zuletzt bearbeitet 21.11.2024 04:16:28
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field a...
CVE-2019-10241
- EPSS 25.44%
- Veröffentlicht 22.04.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:43
In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showi...
CVE-2017-12630
- EPSS 0.72%
- Veröffentlicht 18.12.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Q...
CVE-2010-5312
- EPSS 3.66%
- Veröffentlicht 24.11.2014 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.