Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.1
CVE-2026-18918
- EPSS 0.37%
- Veröffentlicht 28.08.2026 08:54:07
- Zuletzt bearbeitet 01.09.2026 21:11:35
In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those cases, application that based their authz filters upon Lyo-provided `AbstractAdapterCredentialsFilte...
5.3
CVE-2021-41042
- EPSS 0.95%
- Veröffentlicht 07.07.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:25:20
In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.
1