Show filters
48 Total Results
Displaying 21-30 of 48
Sort by:
Attacker Value
Unknown

CVE-2020-19704

Disclosure Date: August 26, 2021 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML.
Attacker Value
Unknown

CVE-2021-21234

Disclosure Date: January 05, 2021 (last updated February 22, 2025)
spring-boot-actuator-logview in a library that adds a simple logfile viewer as spring boot actuator endpoint. It is maven package "eu.hinsch:spring-boot-actuator-logview". In spring-boot-actuator-logview before version 0.2.13 there is a directory traversal vulnerability. The nature of this library is to expose a log file directory via admin (spring boot actuator) HTTP endpoints. Both the filename to view and a base folder (relative to the logging folder root) can be specified via request parameters. While the filename parameter was checked to prevent directory traversal exploits (so that `filename=../somefile` would not work), the base folder parameter was not sufficiently checked, so that `filename=somefile&base=../` could access a file outside the logging base directory). The vulnerability has been patched in release 0.2.13. Any users of 0.2.12 should be able to update without any issues as there are no other changes in that release. There is no workaround to fix the vulnerability o…
Attacker Value
Unknown

CVE-2020-7701

Disclosure Date: August 14, 2020 (last updated February 21, 2025)
madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.
Attacker Value
Unknown

CVE-2020-16165

Disclosure Date: July 30, 2020 (last updated February 21, 2025)
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
Attacker Value
Unknown

CVE-2018-17369

Disclosure Date: September 23, 2018 (last updated November 27, 2024)
An issue was discovered in springboot_authority through 2017-03-06. There is stored XSS via the admin/role/edit roleKey, name, or description parameter.
0
Attacker Value
Unknown

CVE-2017-12881

Disclosure Date: August 18, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in the Spring Batch Admin before 1.3.0 allows remote attackers to hijack the authentication of unspecified victims and submit arbitrary requests, such as exploiting the file upload vulnerability.
0
Attacker Value
Unknown

CVE-2017-12882

Disclosure Date: August 18, 2017 (last updated November 26, 2024)
Stored Cross-site scripting (XSS) vulnerability in Spring Batch Admin before 1.3.0 allows remote authenticated users to inject arbitrary JavaScript or HTML via the file upload functionality.
0
Attacker Value
Unknown

CVE-2016-8357

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. A user with read-only access can send commands to the software and the application will accept those commands. This would allow an attacker with read-only access to make changes within the application.
0
Attacker Value
Unknown

CVE-2016-8378

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application's database lacks sufficient safeguards for protecting credentials.
0
Attacker Value
Unknown

CVE-2016-8361

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication.
0