CVE-2022-22965
- EPSS 94.44%
- Veröffentlicht 01.04.2022 23:15:13
- Zuletzt bearbeitet 10.04.2025 16:56:46
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Sp...
CVE-2022-23437
- EPSS 0.09%
- Veröffentlicht 24.01.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:48:33
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolon...
CVE-2021-40690
- EPSS 0.33%
- Veröffentlicht 19.09.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:24:34
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacke...
CVE-2021-36373
- EPSS 0.15%
- Veröffentlicht 14.07.2021 07:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:37
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prio...
CVE-2021-36374
- EPSS 0.18%
- Veröffentlicht 14.07.2021 07:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:38
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. ...
CVE-2020-17521
- EPSS 0.36%
- Veröffentlicht 07.12.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:08:16
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operatin...
CVE-2020-5421
- EPSS 63.83%
- Veröffentlicht 19.09.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:34:08
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jses...
CVE-2020-1945
- EPSS 0.02%
- Veröffentlicht 14.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:42
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files fr...
CVE-2020-9488
- EPSS 0.01%
- Veröffentlicht 27.04.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:40:45
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Lo...
CVE-2020-5398
- EPSS 90.57%
- Veröffentlicht 17.01.2020 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:04
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response...