Eclipse

Lyo

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 28.08.2026 08:54:07
  • Zuletzt bearbeitet 01.09.2026 21:11:35

In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those cases, application that based their authz filters upon Lyo-provided `AbstractAdapterCredentialsFilte...

Exploit
  • EPSS 0.95%
  • Veröffentlicht 07.07.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:20

In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.