1. [root@ur-test-docker ~]# trivy bytest-harbor.ur.com.cn/api-project/api-esb-test:v1.0.17
    2. 2021-11-10T13:56:26.570+0800 INFO Detected OS: alpine
    3. 2021-11-10T13:56:26.570+0800 INFO Detecting Alpine vulnerabilities...
    4. 2021-11-10T13:56:26.879+0800 INFO Number of language-specific files: 1
    5. 2021-11-10T13:56:26.879+0800 INFO Detecting jar vulnerabilities...
    6. 2021-11-10T13:56:28.428+0800 WARN maven constraint error ([10.5-alpha0,10.5.3.0_1]): failed to new comparer: 2 errors occurred:
    7. * improper constraint: [10.5-alpha0,10.5.3.0_1]
    8. * improper requirements: []
    9. bytest-harbor.ur.com.cn/api-project/api-esb-test:v1.0.17 (alpine 3.13.5)
    10. ========================================================================
    11. Total: 5 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 2, CRITICAL: 3)
    12. +--------------+------------------+----------+-------------------+---------------+---------------------------------------+
    13. | LIBRARY | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION | TITLE |
    14. +--------------+------------------+----------+-------------------+---------------+---------------------------------------+
    15. | apk-tools | CVE-2021-36159 | CRITICAL | 2.12.5-r0 | 2.12.6-r0 | libfetch before 2021-07-26, as |
    16. | | | | | | used in apk-tools, xbps, and |
    17. | | | | | | other products, mishandles... |
    18. | | | | | | -->avd.aquasec.com/nvd/cve-2021-36159 |
    19. +--------------+------------------+ +-------------------+---------------+---------------------------------------+
    20. | libcrypto1.1 | CVE-2021-3711 | | 1.1.1k-r0 | 1.1.1l-r0 | openssl: SM2 Decryption |
    21. | | | | | | Buffer Overflow |
    22. | | | | | | -->avd.aquasec.com/nvd/cve-2021-3711 |
    23. + +------------------+----------+ + +---------------------------------------+
    24. | | CVE-2021-3712 | HIGH | | | openssl: Read buffer overruns |
    25. | | | | | | processing ASN.1 strings |
    26. | | | | | | -->avd.aquasec.com/nvd/cve-2021-3712 |
    27. +--------------+------------------+----------+ + +---------------------------------------+
    28. | libssl1.1 | CVE-2021-3711 | CRITICAL | | | openssl: SM2 Decryption |
    29. | | | | | | Buffer Overflow |
    30. | | | | | | -->avd.aquasec.com/nvd/cve-2021-3711 |
    31. + +------------------+----------+ + +---------------------------------------+
    32. | | CVE-2021-3712 | HIGH | | | openssl: Read buffer overruns |
    33. | | | | | | processing ASN.1 strings |
    34. | | | | | | -->avd.aquasec.com/nvd/cve-2021-3712 |
    35. +--------------+------------------+----------+-------------------+---------------+---------------------------------------+
    36. Java (jar)
    37. ==========
    38. Total: 139 (UNKNOWN: 0, LOW: 7, MEDIUM: 41, HIGH: 57, CRITICAL: 34)
    39. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    40. | LIBRARY | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION | TITLE |
    41. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    42. | com.fasterxml.jackson.core:jackson-databind | CVE-2020-25649 | HIGH | 2.10.0 | 2.10.5.1, 2.9.10.7, 2.6.7.4 | jackson-databind: FasterXML |
    43. | | | | | | DOMDeserializer insecure |
    44. | | | | | | entity expansion is vulnerable |
    45. | | | | | | to XML external entity... |
    46. | | | | | | -->avd.aquasec.com/nvd/cve-2020-25649 |
    47. + +------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    48. | | CVE-2017-15095 | CRITICAL | 2.4.0 | 2.9.4, 2.8.11 | jackson-databind: Unsafe |
    49. | | | | | | deserialization due to |
    50. | | | | | | incomplete black list (incomplete |
    51. | | | | | | fix for CVE-2017-7525)... |
    52. | | | | | | -->avd.aquasec.com/nvd/cve-2017-15095 |
    53. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    54. | | CVE-2017-17485 | | | 2.8.11, 2.9.4 | jackson-databind: Unsafe |
    55. | | | | | | deserialization due to |
    56. | | | | | | incomplete black list (incomplete |
    57. | | | | | | fix for CVE-2017-15095)... |
    58. | | | | | | -->avd.aquasec.com/nvd/cve-2017-17485 |
    59. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    60. | | CVE-2017-7525 | | | 2.7.9.1, 2.6.7.1, 2.8.9 | jackson-databind: Deserialization |
    61. | | | | | | vulnerability via readValue |
    62. | | | | | | method of ObjectMapper |
    63. | | | | | | -->avd.aquasec.com/nvd/cve-2017-7525 |
    64. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    65. | | CVE-2018-11307 | | | 2.8.11.2, 2.7.9.4, 2.9.6 | jackson-databind: Potential |
    66. | | | | | | information exfiltration with |
    67. | | | | | | default typing, serialization |
    68. | | | | | | gadget from MyBatis |
    69. | | | | | | -->avd.aquasec.com/nvd/cve-2018-11307 |
    70. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    71. | | CVE-2018-14718 | | | 2.7.9.5, 2.8.11.3, 2.9.7 | jackson-databind: arbitrary code |
    72. | | | | | | execution in slf4j-ext class |
    73. | | | | | | -->avd.aquasec.com/nvd/cve-2018-14718 |
    74. + +------------------+ + + +---------------------------------------------------------------+
    75. | | CVE-2018-14719 | | | | jackson-databind: arbitrary |
    76. | | | | | | code execution in blaze-ds-opt |
    77. | | | | | | and blaze-ds-core classes |
    78. | | | | | | -->avd.aquasec.com/nvd/cve-2018-14719 |
    79. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    80. | | CVE-2018-7489 | | | 2.8.11.1, 2.9.5 | jackson-databind: incomplete fix |
    81. | | | | | | for CVE-2017-7525 permits unsafe |
    82. | | | | | | serialization via c3p0 libraries |
    83. | | | | | | -->avd.aquasec.com/nvd/cve-2018-7489 |
    84. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    85. | | CVE-2019-14379 | | | 2.9.9.2 | jackson-databind: default |
    86. | | | | | | typing mishandling leading |
    87. | | | | | | to remote code execution |
    88. | | | | | | -->avd.aquasec.com/nvd/cve-2019-14379 |
    89. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    90. | | CVE-2019-14540 | | | 2.9.10 | jackson-databind: |
    91. | | | | | | Serialization gadgets in |
    92. | | | | | | com.zaxxer.hikari.HikariConfig |
    93. | | | | | | -->avd.aquasec.com/nvd/cve-2019-14540 |
    94. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    95. | | CVE-2019-14892 | | | 2.9.10, 2.8.11.5, 2.6.7.3 | jackson-databind: Serialization |
    96. | | | | | | gadgets in classes of the |
    97. | | | | | | commons-configuration package |
    98. | | | | | | -->avd.aquasec.com/nvd/cve-2019-14892 |
    99. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    100. | | CVE-2019-14893 | | | 2.8.11.5, 2.9.10 | jackson-databind: |
    101. | | | | | | Serialization gadgets in |
    102. | | | | | | classes of the xalan package |
    103. | | | | | | -->avd.aquasec.com/nvd/cve-2019-14893 |
    104. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    105. | | CVE-2019-16335 | | | 2.9.10 | jackson-databind: |
    106. | | | | | | Serialization gadgets in |
    107. | | | | | | com.zaxxer.hikari.HikariDataSource |
    108. | | | | | | -->avd.aquasec.com/nvd/cve-2019-16335 |
    109. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    110. | | CVE-2019-16942 | | | 2.9.10.1 | jackson-databind: |
    111. | | | | | | Serialization gadgets in |
    112. | | | | | | org.apache.commons.dbcp.datasources.* |
    113. | | | | | | -->avd.aquasec.com/nvd/cve-2019-16942 |
    114. + +------------------+ + + +---------------------------------------------------------------+
    115. | | CVE-2019-16943 | | | | jackson-databind: |
    116. | | | | | | Serialization gadgets in |
    117. | | | | | | com.p6spy.engine.spy.P6DataSource |
    118. | | | | | | -->avd.aquasec.com/nvd/cve-2019-16943 |
    119. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    120. | | CVE-2019-17267 | | | 2.9.10 | jackson-databind: Serialization |
    121. | | | | | | gadgets in classes of |
    122. | | | | | | the ehcache package |
    123. | | | | | | -->avd.aquasec.com/nvd/cve-2019-17267 |
    124. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    125. | | CVE-2019-17531 | | | 2.9.10.1 | jackson-databind: |
    126. | | | | | | Serialization gadgets in |
    127. | | | | | | org.apache.log4j.receivers.db.* |
    128. | | | | | | -->avd.aquasec.com/nvd/cve-2019-17531 |
    129. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    130. | | CVE-2019-20330 | | | 2.9.10.2, 2.8.11.5 | jackson-databind: lacks |
    131. | | | | | | certain net.sf.ehcache blocking |
    132. | | | | | | -->avd.aquasec.com/nvd/cve-2019-20330 |
    133. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    134. | | CVE-2020-8840 | | | 2.9.10.3, 2.8.11.5 | jackson-databind: Lacks certain |
    135. | | | | | | xbean-reflect/JNDI blocking |
    136. | | | | | | -->avd.aquasec.com/nvd/cve-2020-8840 |
    137. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    138. | | CVE-2020-9547 | | | 2.9.10.4 | jackson-databind: Serialization |
    139. | | | | | | gadgets in ibatis-sqlmap |
    140. | | | | | | -->avd.aquasec.com/nvd/cve-2020-9547 |
    141. + +------------------+ + + +---------------------------------------------------------------+
    142. | | CVE-2020-9548 | | | | jackson-databind: Serialization |
    143. | | | | | | gadgets in anteros-core |
    144. | | | | | | -->avd.aquasec.com/nvd/cve-2020-9548 |
    145. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    146. | | CVE-2018-12022 | HIGH | | 2.8.11.2, 2.7.9.4, 2.9.6 | jackson-databind: improper |
    147. | | | | | | polymorphic deserialization |
    148. | | | | | | of types from Jodd-db library |
    149. | | | | | | -->avd.aquasec.com/nvd/cve-2018-12022 |
    150. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    151. | | CVE-2018-5968 | | | 2.9.4, 2.8.11 | jackson-databind: unsafe |
    152. | | | | | | deserialization due to incomplete |
    153. | | | | | | blacklist (incomplete fix |
    154. | | | | | | for CVE-2017-7525 and... |
    155. | | | | | | -->avd.aquasec.com/nvd/cve-2018-5968 |
    156. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    157. | | CVE-2019-12086 | | | 2.9.9 | jackson-databind: polymorphic |
    158. | | | | | | typing issue allows attacker to |
    159. | | | | | | read arbitrary local files on... |
    160. | | | | | | -->avd.aquasec.com/nvd/cve-2019-12086 |
    161. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    162. | | CVE-2019-14439 | | | 2.9.9.2 | jackson-databind: Polymorphic |
    163. | | | | | | typing issue related to logback/JNDI |
    164. | | | | | | -->avd.aquasec.com/nvd/cve-2019-14439 |
    165. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    166. | | CVE-2020-10673 | | | 2.9.10.4 | jackson-databind: mishandles |
    167. | | | | | | the interaction between |
    168. | | | | | | serialization gadgets and |
    169. | | | | | | typing which could result... |
    170. | | | | | | -->avd.aquasec.com/nvd/cve-2020-10673 |
    171. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    172. | | CVE-2020-25649 | | | 2.10.5.1, 2.9.10.7, 2.6.7.4 | jackson-databind: FasterXML |
    173. | | | | | | DOMDeserializer insecure |
    174. | | | | | | entity expansion is vulnerable |
    175. | | | | | | to XML external entity... |
    176. | | | | | | -->avd.aquasec.com/nvd/cve-2020-25649 |
    177. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    178. | | CVE-2020-35490 | | | 2.9.10.8 | jackson-databind: mishandles the interaction |
    179. | | | | | | between serialization gadgets and typing, related to |
    180. | | | | | | org.apache.commons.dbcp2.datasources.PerUserPoolDataSource... |
    181. | | | | | | -->avd.aquasec.com/nvd/cve-2020-35490 |
    182. + +------------------+ + + +---------------------------------------------------------------+
    183. | | CVE-2020-35491 | | | | jackson-databind: mishandles the interaction |
    184. | | | | | | between serialization gadgets and typing, related to |
    185. | | | | | | org.apache.commons.dbcp2.datasources.SharedPoolDataSource... |
    186. | | | | | | -->avd.aquasec.com/nvd/cve-2020-35491 |
    187. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    188. | | CVE-2021-20190 | | | 2.9.10.7 | jackson-databind: mishandles |
    189. | | | | | | the interaction between |
    190. | | | | | | serialization gadgets and |
    191. | | | | | | typing, related to javax.swing... |
    192. | | | | | | -->avd.aquasec.com/nvd/cve-2021-20190 |
    193. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    194. | | CVE-2018-1000873 | MEDIUM | | 2.9.8 | jackson-modules-java8: DoS due |
    195. | | | | | | to an Improper Input Validation |
    196. | | | | | | -->avd.aquasec.com/nvd/cve-2018-1000873 |
    197. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    198. | | CVE-2019-12384 | | | 2.9.9.1 | jackson-databind: failure |
    199. | | | | | | to block the logback-core |
    200. | | | | | | class from polymorphic |
    201. | | | | | | deserialization leading to... |
    202. | | | | | | -->avd.aquasec.com/nvd/cve-2019-12384 |
    203. + +------------------+ + + +---------------------------------------------------------------+
    204. | | CVE-2019-12814 | | | | jackson-databind: polymorphic |
    205. | | | | | | typing issue allows attacker to |
    206. | | | | | | read arbitrary local files on... |
    207. | | | | | | -->avd.aquasec.com/nvd/cve-2019-12814 |
    208. +--------------------------------------------------------------------+------------------+ +-------------------+--------------------------------+---------------------------------------------------------------+
    209. | com.google.guava:guava | CVE-2018-10237 | | 19.0 | 24.1.1 | guava: Unbounded memory |
    210. | | | | | | allocation in AtomicDoubleArray |
    211. | | | | | | and CompoundOrdering classes |
    212. | | | | | | allow remote attackers... |
    213. | | | | | | -->avd.aquasec.com/nvd/cve-2018-10237 |
    214. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    215. | | CVE-2020-8908 | LOW | | 30.0-jre | guava: local information |
    216. | | | | | | disclosure via temporary directory |
    217. | | | | | | created with unsafe permissions |
    218. | | | | | | -->avd.aquasec.com/nvd/cve-2020-8908 |
    219. + +------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    220. | | CVE-2018-10237 | MEDIUM | 22.0 | 24.1.1 | guava: Unbounded memory |
    221. | | | | | | allocation in AtomicDoubleArray |
    222. | | | | | | and CompoundOrdering classes |
    223. | | | | | | allow remote attackers... |
    224. | | | | | | -->avd.aquasec.com/nvd/cve-2018-10237 |
    225. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    226. | | CVE-2020-8908 | LOW | | 30.0-jre | guava: local information |
    227. | | | | | | disclosure via temporary directory |
    228. | | | | | | created with unsafe permissions |
    229. | | | | | | -->avd.aquasec.com/nvd/cve-2020-8908 |
    230. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    231. | com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer | CVE-2021-42575 | CRITICAL | r239 | 20211018.1 | Policies not properly enforced |
    232. | | | | | | in OWASP Java HTML Sanitizer |
    233. | | | | | | -->avd.aquasec.com/nvd/cve-2021-42575 |
    234. +--------------------------------------------------------------------+------------------+ +-------------------+--------------------------------+---------------------------------------------------------------+
    235. | com.mchange:c3p0 | CVE-2018-20433 | | 0.9.5.2 | 0.9.5.3 | c3p0: XML external entity processing |
    236. | | | | | | in extractXmlConfigFromInputStream |
    237. | | | | | | -->avd.aquasec.com/nvd/cve-2018-20433 |
    238. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    239. | | CVE-2019-5427 | HIGH | | 0.9.5.4 | c3p0: loading XML configuration |
    240. | | | | | | leads to denial of service |
    241. | | | | | | -->avd.aquasec.com/nvd/cve-2019-5427 |
    242. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    243. | com.squareup.okhttp3:okhttp | CVE-2018-20200 | MEDIUM | 3.10.0 | 3.12.1 | okhttp: certificate pinning bypass |
    244. | | | | | | -->avd.aquasec.com/nvd/cve-2018-20200 |
    245. +--------------------------------------------------------------------+------------------+ +-------------------+--------------------------------+---------------------------------------------------------------+
    246. | com.squareup.okhttp:okhttp | CVE-2016-2402 | | 2.7.5 | 3.1.2 | Improper Certificate Validation |
    247. | | | | | | -->avd.aquasec.com/nvd/cve-2016-2402 |
    248. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    249. | commons-beanutils:commons-beanutils | CVE-2019-10086 | HIGH | 1.9.3 | 1.9.4 | apache-commons-beanutils: does |
    250. | | | | | | not suppresses the class property |
    251. | | | | | | in PropertyUtilsBean by default |
    252. | | | | | | -->avd.aquasec.com/nvd/cve-2019-10086 |
    253. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    254. | commons-fileupload:commons-fileupload | CVE-2016-1000031 | CRITICAL | 1.3.1 | 1.3.3 | Apache Commons FileUpload: |
    255. | | | | | | DiskFileItem file manipulation |
    256. | | | | | | -->avd.aquasec.com/nvd/cve-2016-1000031 |
    257. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    258. | | CVE-2016-3092 | HIGH | | 1.3.2 | tomcat: Usage of vulnerable |
    259. | | | | | | FileUpload package can result |
    260. | | | | | | in denial of service... |
    261. | | | | | | -->avd.aquasec.com/nvd/cve-2016-3092 |
    262. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    263. | commons-httpclient:commons-httpclient | CVE-2012-5783 | MEDIUM | 3.1 | | jakarta-commons-httpclient: |
    264. | | | | | | missing connection hostname check |
    265. | | | | | | against X.509 certificate name |
    266. | | | | | | -->avd.aquasec.com/nvd/cve-2012-5783 |
    267. +--------------------------------------------------------------------+------------------+ +-------------------+--------------------------------+---------------------------------------------------------------+
    268. | commons-io:commons-io | CVE-2021-29425 | | 2.5 | 2.7 | apache-commons-io: Limited |
    269. | | | | | | path traversal in Apache |
    270. | | | | | | Commons IO 2.2 to 2.6 |
    271. | | | | | | -->avd.aquasec.com/nvd/cve-2021-29425 |
    272. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    273. | io.netty:netty | CVE-2019-20444 | CRITICAL | 3.7.0.Final | 4.1.44.Final | netty: HTTP request smuggling |
    274. | | | | | | -->avd.aquasec.com/nvd/cve-2019-20444 |
    275. + +------------------+ + + +---------------------------------------------------------------+
    276. | | CVE-2019-20445 | | | | netty: HttpObjectDecoder.java allows |
    277. | | | | | | Content-Length header to accompanied |
    278. | | | | | | by second Content-Length header |
    279. | | | | | | -->avd.aquasec.com/nvd/cve-2019-20445 |
    280. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    281. | | CVE-2019-16869 | HIGH | | 4.1.42.Final | netty: HTTP request smuggling |
    282. | | | | | | by mishandled whitespace |
    283. | | | | | | before the colon in HTTP... |
    284. | | | | | | -->avd.aquasec.com/nvd/cve-2019-16869 |
    285. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    286. | | CVE-2021-21290 | MEDIUM | | 4.1.59.Final | netty: Information disclosure via |
    287. | | | | | | the local system temporary directory |
    288. | | | | | | -->avd.aquasec.com/nvd/cve-2021-21290 |
    289. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    290. | | CVE-2021-21295 | | | 4.1.60.Final | netty: possible request smuggling |
    291. | | | | | | in HTTP/2 due missing validation |
    292. | | | | | | -->avd.aquasec.com/nvd/cve-2021-21295 |
    293. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    294. | | CVE-2021-21409 | | | 4.1.61.Final | netty: Request smuggling |
    295. | | | | | | via content-length header |
    296. | | | | | | -->avd.aquasec.com/nvd/cve-2021-21409 |
    297. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    298. | io.netty:netty-all | CVE-2019-16869 | HIGH | 4.1.17.Final | 4.1.42 | netty: HTTP request smuggling |
    299. | | | | | | by mishandled whitespace |
    300. | | | | | | before the colon in HTTP... |
    301. | | | | | | -->avd.aquasec.com/nvd/cve-2019-16869 |
    302. +--------------------------------------------------------------------+------------------+ +-------------------+--------------------------------+---------------------------------------------------------------+
    303. | io.netty:netty-codec | CVE-2021-37136 | | 4.1.42.Final | 4.1.68.Final | netty-codec: Bzip2Decoder |
    304. | | | | | | doesn't allow setting size |
    305. | | | | | | restrictions for decompressed data |
    306. | | | | | | -->avd.aquasec.com/nvd/cve-2021-37136 |
    307. + +------------------+ + + +---------------------------------------------------------------+
    308. | | CVE-2021-37137 | | | | netty-codec: SnappyFrameDecoder |
    309. | | | | | | doesn't restrict chunk length and |
    310. | | | | | | may buffer skippable chunks in... |
    311. | | | | | | -->avd.aquasec.com/nvd/cve-2021-37137 |
    312. +--------------------------------------------------------------------+------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    313. | io.netty:netty-codec-http | CVE-2021-21290 | MEDIUM | | 4.1.59.Final | netty: Information disclosure via |
    314. | | | | | | the local system temporary directory |
    315. | | | | | | -->avd.aquasec.com/nvd/cve-2021-21290 |
    316. +--------------------------------------------------------------------+------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    317. | io.netty:netty-handler | CVE-2019-20444 | CRITICAL | | 4.1.44 | netty: HTTP request smuggling |
    318. | | | | | | -->avd.aquasec.com/nvd/cve-2019-20444 |
    319. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    320. | | CVE-2019-20445 | | | 4.1.45 | netty: HttpObjectDecoder.java allows |
    321. | | | | | | Content-Length header to accompanied |
    322. | | | | | | by second Content-Length header |
    323. | | | | | | -->avd.aquasec.com/nvd/cve-2019-20445 |
    324. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    325. | | CVE-2020-11612 | HIGH | | 4.1.46 | netty: compression/decompression |
    326. | | | | | | codecs don't enforce limits |
    327. | | | | | | on buffer allocation sizes |
    328. | | | | | | -->avd.aquasec.com/nvd/cve-2020-11612 |
    329. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    330. | jline:jline | CVE-2010-1330 | MEDIUM | 0.9.94 | 1.4.1 | jruby: XSS in the regular |
    331. | | | | | | expression engine when |
    332. | | | | | | processing invalid UTF-8 byte... |
    333. | | | | | | -->avd.aquasec.com/nvd/cve-2010-1330 |
    334. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    335. | | CVE-2013-2035 | | | 2.11 | HawtJNI: predictable temporary |
    336. | | | | | | file name leading to local |
    337. | | | | | | arbitrary code execution |
    338. | | | | | | -->avd.aquasec.com/nvd/cve-2013-2035 |
    339. +--------------------------------------------------------------------+------------------+ +-------------------+--------------------------------+---------------------------------------------------------------+
    340. | junit:junit | CVE-2020-15250 | | 4.12 | 4.13.1 | junit4: TemporaryFolder is |
    341. | | | | | | shared between all users across |
    342. | | | | | | system which could result... |
    343. | | | | | | -->avd.aquasec.com/nvd/cve-2020-15250 |
    344. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    345. | log4j:log4j | CVE-2019-17571 | CRITICAL | 1.2.16 | | log4j: deserialization of |
    346. | | | | | | untrusted data in SocketServer |
    347. | | | | | | -->avd.aquasec.com/nvd/cve-2019-17571 |
    348. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    349. | | CVE-2020-9488 | LOW | | 2.13.2 | log4j: improper validation |
    350. | | | | | | of certificate with host |
    351. | | | | | | mismatch in SMTP appender |
    352. | | | | | | -->avd.aquasec.com/nvd/cve-2020-9488 |
    353. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    354. | mysql:mysql-connector-java | CVE-2020-2934 | MEDIUM | 8.0.18 | 5.1.49, 8.0.20 | mysql-connector-java: allows |
    355. | | | | | | unauthenticated attacker with |
    356. | | | | | | network access via multiple |
    357. | | | | | | protocols to compromise... |
    358. | | | | | | -->avd.aquasec.com/nvd/cve-2020-2934 |
    359. +--------------------------------------------------------------------+------------------+ +-------------------+--------------------------------+---------------------------------------------------------------+
    360. | org.apache.activemq:activemq-broker | CVE-2020-13947 | | 5.15.10 | 5.15.14, 5.16.1 | Cross-site Scripting |
    361. | | | | | | -->avd.aquasec.com/nvd/cve-2020-13947 |
    362. +--------------------------------------------------------------------+ + + + + +
    363. | org.apache.activemq:activemq-client | | | | | |
    364. | | | | | | |
    365. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    366. | org.apache.ant:ant | CVE-2020-11979 | HIGH | 1.9.1 | 1.10.9 | ant: insecure temporary file |
    367. | | | | | | -->avd.aquasec.com/nvd/cve-2020-11979 |
    368. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    369. | | CVE-2020-1945 | MEDIUM | | 1.10.8, 1.9.15 | ant: insecure temporary |
    370. | | | | | | file vulnerability |
    371. | | | | | | -->avd.aquasec.com/nvd/cve-2020-1945 |
    372. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    373. | | CVE-2021-36373 | | | 1.10.11, 1.9.16 | ant: excessive memory |
    374. | | | | | | allocation when reading a |
    375. | | | | | | specially crafted TAR archive |
    376. | | | | | | -->avd.aquasec.com/nvd/cve-2021-36373 |
    377. + +------------------+ + + +---------------------------------------------------------------+
    378. | | CVE-2021-36374 | | | | ant: excessive memory allocation |
    379. | | | | | | when reading a specially |
    380. | | | | | | crafted ZIP archive or... |
    381. | | | | | | -->avd.aquasec.com/nvd/cve-2021-36374 |
    382. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    383. | org.apache.commons:commons-compress | CVE-2021-35515 | HIGH | 1.4.1 | 1.21 | apache-commons-compress: |
    384. | | | | | | infinite loop when reading a |
    385. | | | | | | specially crafted 7Z archive |
    386. | | | | | | -->avd.aquasec.com/nvd/cve-2021-35515 |
    387. + +------------------+ + + +---------------------------------------------------------------+
    388. | | CVE-2021-35516 | | | | apache-commons-compress: excessive |
    389. | | | | | | memory allocation when reading |
    390. | | | | | | a specially crafted 7Z archive |
    391. | | | | | | -->avd.aquasec.com/nvd/cve-2021-35516 |
    392. + +------------------+ + + +---------------------------------------------------------------+
    393. | | CVE-2021-35517 | | | | apache-commons-compress: excessive |
    394. | | | | | | memory allocation when reading |
    395. | | | | | | a specially crafted TAR archive |
    396. | | | | | | -->avd.aquasec.com/nvd/cve-2021-35517 |
    397. + +------------------+ + + +---------------------------------------------------------------+
    398. | | CVE-2021-36090 | | | | apache-commons-compress: excessive |
    399. | | | | | | memory allocation when reading |
    400. | | | | | | a specially crafted ZIP archive |
    401. | | | | | | -->avd.aquasec.com/nvd/cve-2021-36090 |
    402. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    403. | | CVE-2018-11771 | MEDIUM | | 1.18 | apache-commons-compress: |
    404. | | | | | | ZipArchiveInputStream.read() |
    405. | | | | | | fails to identify correct EOF |
    406. | | | | | | allowing for DoS via crafted... |
    407. | | | | | | -->avd.aquasec.com/nvd/cve-2018-11771 |
    408. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    409. | org.apache.hadoop:hadoop-common | CVE-2018-8009 | HIGH | 2.7.4 | 2.7.7, 2.8.5, 2.9.2, 3.1.1 | hadoop: arbitrary file write |
    410. | | | | | | vulnerability / arbitrary code |
    411. | | | | | | execution using a specially... |
    412. | | | | | | -->avd.aquasec.com/nvd/cve-2018-8009 |
    413. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    414. | | CVE-2018-8029 | | | 2.8.5, 2.9.2, 3.1.1 | hadoop: a user who can escalate |
    415. | | | | | | to yarn user can possibly run... |
    416. | | | | | | -->avd.aquasec.com/nvd/cve-2018-8029 |
    417. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    418. | | CVE-2017-15713 | MEDIUM | | 2.8.3, 3.0.1 | Moderate severity vulnerability that |
    419. | | | | | | affects org.apache.hadoop:hadoop-main |
    420. | | | | | | -->avd.aquasec.com/nvd/cve-2017-15713 |
    421. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    422. | org.apache.hive:hive-jdbc | CVE-2018-1282 | CRITICAL | 1.1.0 | 2.3.3 | hive: Improper input validation |
    423. | | | | | | in jdbc/HivePreparedStatement.java |
    424. | | | | | | allows for SQL injection |
    425. | | | | | | -->avd.aquasec.com/nvd/cve-2018-1282 |
    426. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    427. | | CVE-2018-1314 | MEDIUM | | 3.1.1, 2.3.4 | Py-hiverunner 5.0.0 updates the |
    428. | | | | | | default supported Hive version |
    429. | | | | | | to 2.3.4 because version... |
    430. | | | | | | -->avd.aquasec.com/nvd/cve-2018-1314 |
    431. +--------------------------------------------------------------------+------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    432. | org.apache.hive:hive-service | CVE-2015-1772 | HIGH | | 1.1.1, 1.0.1 | Apache Hive: authentication |
    433. | | | | | | vulnerability in HiveServer2 |
    434. | | | | | | -->avd.aquasec.com/nvd/cve-2015-1772 |
    435. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    436. | | CVE-2015-7521 | | | 1.2.2 | High severity vulnerability that |
    437. | | | | | | affects org.apache.hive:hive, |
    438. | | | | | | org.apache.hive:hive-exec, and |
    439. | | | | | | org.apache.hive:hive-service |
    440. | | | | | | -->avd.aquasec.com/nvd/cve-2015-7521 |
    441. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    442. | | CVE-2016-3083 | | | 2.0.1, 1.2.2 | Moderate severity vulnerability |
    443. | | | | | | that affects org.apache.hive:hive, |
    444. | | | | | | org.apache.hive:hive-exec, and |
    445. | | | | | | org.apache.hive:hive-service |
    446. | | | | | | -->avd.aquasec.com/nvd/cve-2016-3083 |
    447. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    448. | | CVE-2018-1284 | LOW | | 2.3.3 | hive: Mishandled input in |
    449. | | | | | | UDFXPathUtil.java allows users |
    450. | | | | | | to access arbitrary files via... |
    451. | | | | | | -->avd.aquasec.com/nvd/cve-2018-1284 |
    452. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    453. | org.apache.httpcomponents:httpclient | CVE-2020-13956 | MEDIUM | 4.5.10 | 5.0.3, 4.5.13 | apache-httpclient: incorrect |
    454. | | | | | | handling of malformed authority |
    455. | | | | | | component in request URIs |
    456. | | | | | | -->avd.aquasec.com/nvd/cve-2020-13956 |
    457. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    458. | org.apache.logging.log4j:log4j-core | CVE-2020-9488 | LOW | 2.12.1 | 2.13.2 | log4j: improper validation |
    459. | | | | | | of certificate with host |
    460. | | | | | | mismatch in SMTP appender |
    461. | | | | | | -->avd.aquasec.com/nvd/cve-2020-9488 |
    462. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    463. | org.apache.poi:poi | CVE-2019-12415 | MEDIUM | 3.17 | 4.1.1 | poi: a specially crafted |
    464. | | | | | | Microsoft Excel document allows |
    465. | | | | | | attacker to read files... |
    466. | | | | | | -->avd.aquasec.com/nvd/cve-2019-12415 |
    467. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    468. | org.apache.thrift:libthrift | CVE-2018-1320 | HIGH | 0.9.2 | 0.12.0 | thrift: SASL negotiation |
    469. | | | | | | isComplete validation bypass in the |
    470. | | | | | | org.apache.thrift.transport.TSaslTransport |
    471. | | | | | | class -->avd.aquasec.com/nvd/cve-2018-1320 |
    472. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    473. | | CVE-2019-0205 | | | 0.13.0 | thrift: Endless loop when |
    474. | | | | | | feed with specific input data |
    475. | | | | | | -->avd.aquasec.com/nvd/cve-2019-0205 |
    476. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    477. | | CVE-2015-3254 | MEDIUM | | 0.9.3 | thrift: Infinite recursion via |
    478. | | | | | | vectors involving the skip function |
    479. | | | | | | -->avd.aquasec.com/nvd/cve-2015-3254 |
    480. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    481. | | CVE-2018-11798 | | | 0.12.0 | thrift: Improper Access |
    482. | | | | | | Control grants access to files |
    483. | | | | | | outside the webservers... |
    484. | | | | | | -->avd.aquasec.com/nvd/cve-2018-11798 |
    485. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    486. | org.apache.tomcat.embed:tomcat-embed-core | CVE-2020-1938 | CRITICAL | 9.0.27 | 7.0.100, 8.5.51, 9.0.31 | tomcat: Apache Tomcat AJP File |
    487. | | | | | | Read/Inclusion Vulnerability |
    488. | | | | | | -->avd.aquasec.com/nvd/cve-2020-1938 |
    489. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    490. | | CVE-2019-12418 | HIGH | | 9.0.29, 8.5.49, 7.0.99 | tomcat: local privilege escalation |
    491. | | | | | | -->avd.aquasec.com/nvd/cve-2019-12418 |
    492. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    493. | | CVE-2019-17563 | | | 9.0.30, 8.5.50, 7.0.99 | tomcat: Session fixation when |
    494. | | | | | | using FORM authentication |
    495. | | | | | | -->avd.aquasec.com/nvd/cve-2019-17563 |
    496. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    497. | | CVE-2020-13934 | | | 8.5.57, 9.0.37 | tomcat: OutOfMemoryException |
    498. | | | | | | caused by HTTP/2 connection |
    499. | | | | | | leak could lead to DoS |
    500. | | | | | | -->avd.aquasec.com/nvd/cve-2020-13934 |
    501. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    502. | | CVE-2020-17527 | | | 8.5.60, 9.0.40, 10.0.2 | tomcat: HTTP/2 request header mix-up |
    503. | | | | | | -->avd.aquasec.com/nvd/cve-2020-17527 |
    504. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    505. | | CVE-2020-9484 | | | 7.0.104, 8.5.55, 9.0.35, | tomcat: deserialization |
    506. | | | | | 10.0.0-M5 | flaw in session persistence |
    507. | | | | | | storage leading to RCE |
    508. | | | | | | -->avd.aquasec.com/nvd/cve-2020-9484 |
    509. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    510. | | CVE-2021-25122 | | | 8.5.63, 9.0.43, 10.0.2 | tomcat: Request mix-up with h2c |
    511. | | | | | | -->avd.aquasec.com/nvd/cve-2021-25122 |
    512. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    513. | | CVE-2021-25329 | | | 7.0.108, 8.5.61, 9.0.41, | tomcat: Incomplete fix |
    514. | | | | | 10.0.2 | for CVE-2020-9484 (RCE |
    515. | | | | | | via session persistence) |
    516. | | | | | | -->avd.aquasec.com/nvd/cve-2021-25329 |
    517. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    518. | | CVE-2020-1935 | MEDIUM | | 9.0.31, 8.5.51, 7.0.100 | tomcat: Mishandling of |
    519. | | | | | | Transfer-Encoding header allows |
    520. | | | | | | for HTTP request smuggling |
    521. | | | | | | -->avd.aquasec.com/nvd/cve-2020-1935 |
    522. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    523. | | CVE-2021-24122 | | | 7.0.107, 8.5.60, 9.0.40, | tomcat: Information disclosure |
    524. | | | | | 10.0.0-M10 | when using NTFS file system |
    525. | | | | | | -->avd.aquasec.com/nvd/cve-2021-24122 |
    526. +--------------------------------------------------------------------+------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    527. | org.apache.tomcat.embed:tomcat-embed-websocket | CVE-2020-13935 | HIGH | | 7.0.105, 8.5.57, 9.0.37, | tomcat: multiple requests |
    528. | | | | | 10.0.2 | with invalid payload length |
    529. | | | | | | in a WebSocket frame could... |
    530. | | | | | | -->avd.aquasec.com/nvd/cve-2020-13935 |
    531. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    532. | | CVE-2021-24122 | MEDIUM | | 10.0.0-M10, 9.0.40, 8.5.60, | tomcat: Information disclosure |
    533. | | | | | 7.0.107 | when using NTFS file system |
    534. | | | | | | -->avd.aquasec.com/nvd/cve-2021-24122 |
    535. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    536. | org.apache.xmlbeans:xmlbeans | CVE-2021-23926 | CRITICAL | 2.6.0 | 3.0.0 | xmlbeans: allowed malicious |
    537. | | | | | | XML input may lead to XML |
    538. | | | | | | Entity Expansion attack... |
    539. | | | | | | -->avd.aquasec.com/nvd/cve-2021-23926 |
    540. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    541. | org.apache.zookeeper:zookeeper | CVE-2017-5637 | HIGH | 3.4.6 | 3.4.10, 3.5.3 | zookeeper: Incorrect |
    542. | | | | | | input validation with |
    543. | | | | | | wchp/wchc four letter words |
    544. | | | | | | -->avd.aquasec.com/nvd/cve-2017-5637 |
    545. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    546. | | CVE-2018-8012 | | | 3.4.10, 3.5.4 | zookeeper: No authentication |
    547. | | | | | | or authorization is enforced |
    548. | | | | | | when a server joins a... |
    549. | | | | | | -->avd.aquasec.com/nvd/cve-2018-8012 |
    550. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    551. | | CVE-2019-0201 | MEDIUM | | 3.5.5, 3.4.14 | zookeeper: Information |
    552. | | | | | | disclosure in Apache ZooKeeper |
    553. | | | | | | -->avd.aquasec.com/nvd/cve-2019-0201 |
    554. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    555. | org.codehaus.jackson:jackson-mapper-asl | CVE-2019-10172 | HIGH | 1.9.13 | | jackson-mapper-asl: XML external |
    556. | | | | | | entity similar to CVE-2016-3720 |
    557. | | | | | | -->avd.aquasec.com/nvd/cve-2019-10172 |
    558. +--------------------------------------------------------------------+------------------+ +-------------------+--------------------------------+---------------------------------------------------------------+
    559. | org.eclipse.jetty:jetty-http | CVE-2020-27216 | | 8.1.14.v20131031 | 9.3.29.v20201019, | jetty: local temporary directory |
    560. | | | | | 9.4.32.v20200930, 11.0.1 | hijacking vulnerability |
    561. | | | | | | -->avd.aquasec.com/nvd/cve-2020-27216 |
    562. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    563. | | CVE-2021-28165 | | | 9.4.39.v20210325, 10.0.2, | jetty: Resource exhaustion when |
    564. | | | | | 11.0.2 | receiving an invalid large TLS frame |
    565. | | | | | | -->avd.aquasec.com/nvd/cve-2021-28165 |
    566. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    567. | | CVE-2019-10247 | MEDIUM | | 9.2.28.v20190418, | jetty: error path |
    568. | | | | | 9.3.27.v20190418, | information disclosure |
    569. | | | | | 9.4.17.v20190418 | -->avd.aquasec.com/nvd/cve-2019-10247 |
    570. +--------------------------------------------------------------------+------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    571. | org.eclipse.jetty:jetty-io | CVE-2021-28165 | HIGH | | 10.0.2, 9.4.39, 11.0.2 | jetty: Resource exhaustion when |
    572. | | | | | | receiving an invalid large TLS frame |
    573. | | | | | | -->avd.aquasec.com/nvd/cve-2021-28165 |
    574. +--------------------------------------------------------------------+------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    575. | org.eclipse.jetty:jetty-server | CVE-2017-7657 | CRITICAL | | 9.3.24.v20180605, | jetty: HTTP request smuggling |
    576. | | | | | 9.2.25.v20180606 | -->avd.aquasec.com/nvd/cve-2017-7657 |
    577. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    578. | | CVE-2017-7658 | | | 9.2.26.v20180806, | jetty: Incorrect header handling |
    579. | | | | | 9.3.24.v20180605, | -->avd.aquasec.com/nvd/cve-2017-7658 |
    580. | | | | | 9.4.11.v20180605 | |
    581. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    582. | | CVE-2015-2080 | HIGH | | 9.2.9.v20150224 | jetty: remote unauthenticated |
    583. | | | | | | credential exposure |
    584. | | | | | | -->avd.aquasec.com/nvd/cve-2015-2080 |
    585. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    586. | | CVE-2017-7656 | | | 9.4.11.v20180605, | jetty: HTTP request smuggling |
    587. | | | | | 9.3.24.v20180605 | using the range header |
    588. | | | | | | -->avd.aquasec.com/nvd/cve-2017-7656 |
    589. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    590. | | CVE-2020-27216 | | | 9.3.29.v20201019, | jetty: local temporary directory |
    591. | | | | | 9.4.32.v20200930, 11.0.1 | hijacking vulnerability |
    592. | | | | | | -->avd.aquasec.com/nvd/cve-2020-27216 |
    593. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    594. | | CVE-2021-28165 | | | 9.4.39.v20210325, 10.0.2, | jetty: Resource exhaustion when |
    595. | | | | | 11.0.2 | receiving an invalid large TLS frame |
    596. | | | | | | -->avd.aquasec.com/nvd/cve-2021-28165 |
    597. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    598. | | CVE-2019-10241 | MEDIUM | | 9.4.16.v20190411, | jetty: using specially formatted |
    599. | | | | | 9.3.26.v20190403, | URL against DefaultServlet or |
    600. | | | | | 9.2.27.v20190403 | ResourceHandler leads to XSS... |
    601. | | | | | | -->avd.aquasec.com/nvd/cve-2019-10241 |
    602. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    603. | | CVE-2019-10247 | | | 9.4.17.v20190418, | jetty: error path |
    604. | | | | | 9.3.27.v20190418, | information disclosure |
    605. | | | | | 9.2.28.v20190418 | -->avd.aquasec.com/nvd/cve-2019-10247 |
    606. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    607. | | CVE-2021-34428 | LOW | | 11.0.3, 10.0.3, 9.4.41 | jetty: SessionListener can |
    608. | | | | | | prevent a session from being |
    609. | | | | | | invalidated breaking logout |
    610. | | | | | | -->avd.aquasec.com/nvd/cve-2021-34428 |
    611. +--------------------------------------------------------------------+------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    612. | org.eclipse.jetty:jetty-util | CVE-2017-9735 | HIGH | | 9.4.6.v20170531 | jetty: Timing channel attack |
    613. | | | | | | in util/security/Password.java |
    614. | | | | | | -->avd.aquasec.com/nvd/cve-2017-9735 |
    615. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    616. | | CVE-2020-27216 | | | 9.3.29.v20201019, | jetty: local temporary directory |
    617. | | | | | 9.4.32.v20200930, 11.0.1 | hijacking vulnerability |
    618. | | | | | | -->avd.aquasec.com/nvd/cve-2020-27216 |
    619. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    620. | | CVE-2021-28165 | | | 9.4.39.v20210325, 10.0.2, | jetty: Resource exhaustion when |
    621. | | | | | 11.0.2 | receiving an invalid large TLS frame |
    622. | | | | | | -->avd.aquasec.com/nvd/cve-2021-28165 |
    623. +--------------------------------------------------------------------+------------------+ +-------------------+--------------------------------+---------------------------------------------------------------+
    624. | org.eclipse.paho:org.eclipse.paho.client.mqttv3 | CVE-2019-11777 | | 1.2.0 | 1.2.1 | org.eclipse.paho.client.mqttv3: |
    625. | | | | | | Improper hostname validation |
    626. | | | | | | in the MQTT library |
    627. | | | | | | -->avd.aquasec.com/nvd/cve-2019-11777 |
    628. +--------------------------------------------------------------------+------------------+ +-------------------+--------------------------------+---------------------------------------------------------------+
    629. | org.elasticsearch:elasticsearch | CVE-2020-7014 | | 6.8.3 | 7.6.2, 6.8.8 | elasticsearch: Incomplete fix |
    630. | | | | | | for CVE-2020-7009 could result |
    631. | | | | | | in generating API key with... |
    632. | | | | | | -->avd.aquasec.com/nvd/cve-2020-7014 |
    633. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    634. | | CVE-2021-22135 | MEDIUM | | 6.8.15, 7.11.2 | elasticsearch: Document disclosure |
    635. | | | | | | flaw in the Elasticsearch suggester |
    636. | | | | | | -->avd.aquasec.com/nvd/cve-2021-22135 |
    637. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    638. | | CVE-2021-22144 | | | 7.13.3, 6.8.17 | elasticsearch: uncontrolled |
    639. | | | | | | recursion in Grok parser |
    640. | | | | | | -->avd.aquasec.com/nvd/cve-2021-22144 |
    641. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    642. | | CVE-2020-7020 | LOW | | 7.9.2, 6.8.13 | elasticsearch: not properly |
    643. | | | | | | preserving security |
    644. | | | | | | permissions when executing |
    645. | | | | | | complex queries may lead... |
    646. | | | | | | -->avd.aquasec.com/nvd/cve-2020-7020 |
    647. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    648. | org.hibernate.validator:hibernate-validator | CVE-2019-10219 | MEDIUM | 6.0.17.Final | 6.0.18 | hibernate-validator: |
    649. | | | | | | safeHTML validator allows XSS |
    650. | | | | | | -->avd.aquasec.com/nvd/cve-2019-10219 |
    651. + +------------------+ + +--------------------------------+---------------------------------------------------------------+
    652. | | CVE-2020-10693 | | | 6.0.20.Final, 6.1.5.Final | hibernate-validator: Improper input |
    653. | | | | | | validation in the interpolation |
    654. | | | | | | of constraint error messages |
    655. | | | | | | -->avd.aquasec.com/nvd/cve-2020-10693 |
    656. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    657. | org.jdom:jdom2 | CVE-2021-33813 | HIGH | 2.0.6 | | jdom: XXE allows attackers to |
    658. | | | | | | cause a DoS via a crafted HTTP... |
    659. | | | | | | -->avd.aquasec.com/nvd/cve-2021-33813 |
    660. +--------------------------------------------------------------------+------------------+ +-------------------+--------------------------------+---------------------------------------------------------------+
    661. | org.mybatis:mybatis | CVE-2020-26945 | | 3.5.0 | 3.5.6 | mybatis: mishandles deserialization |
    662. | | | | | | of object streams which could |
    663. | | | | | | result in remote code... |
    664. | | | | | | -->avd.aquasec.com/nvd/cve-2020-26945 |
    665. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    666. | org.quartz-scheduler:quartz | CVE-2019-13990 | CRITICAL | 2.3.1 | 2.3.2 | libquartz: XXE attacks |
    667. | | | | | | via job description |
    668. | | | | | | -->avd.aquasec.com/nvd/cve-2019-13990 |
    669. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    670. | org.springframework:spring-webmvc | CVE-2020-5398 | HIGH | 5.2.0.RELEASE | 5.0.16, 5.1.13, 5.2.3 | springframework: RFD attack via |
    671. | | | | | | Content-Disposition Header sourced |
    672. | | | | | | from request input by Spring... |
    673. | | | | | | -->avd.aquasec.com/nvd/cve-2020-5398 |
    674. + +------------------+----------+ +--------------------------------+---------------------------------------------------------------+
    675. | | CVE-2020-5397 | MEDIUM | | 5.2.3 | springframework: CSRF attack |
    676. | | | | | | via CORS Preflight Requests |
    677. | | | | | | with Spring MVC or Spring... |
    678. | | | | | | -->avd.aquasec.com/nvd/cve-2020-5397 |
    679. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    680. | org.yaml:snakeyaml | CVE-2017-18640 | HIGH | 1.25 | 1.26 | snakeyaml: Billion laughs |
    681. | | | | | | attack via alias feature |
    682. | | | | | | -->avd.aquasec.com/nvd/cve-2017-18640 |
    683. +--------------------------------------------------------------------+------------------+----------+-------------------+--------------------------------+---------------------------------------------------------------+
    684. [root@ur-test-docker ~]#