Show filters
79 Total Results
Displaying 31-40 of 79
Sort by:
Attacker Value
Unknown

CVE-2022-4147

Disclosure Date: December 06, 2022 (last updated October 08, 2023)
Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on the object returned by the XMLHttpRequest upload property and have no ReadableStream object used in the request.
Attacker Value
Unknown

CVE-2022-4116

Disclosure Date: November 22, 2022 (last updated October 08, 2023)
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.
Attacker Value
Unknown

CVE-2022-42003

Disclosure Date: October 02, 2022 (last updated December 20, 2023)
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.
Attacker Value
Unknown

CVE-2022-42004

Disclosure Date: October 02, 2022 (last updated December 22, 2024)
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.
Attacker Value
Unknown

CVE-2022-2466

Disclosure Date: August 31, 2022 (last updated October 08, 2023)
It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.
Attacker Value
Unknown

CVE-2022-1259

Disclosure Date: August 31, 2022 (last updated November 29, 2024)
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
Attacker Value
Unknown

CVE-2022-0084

Disclosure Date: August 26, 2022 (last updated October 08, 2023)
A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possibly causing log contention-related performance concerns or an unwanted disk fill-up.
Attacker Value
Unknown

CVE-2021-3669

Disclosure Date: August 26, 2022 (last updated October 08, 2023)
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
Attacker Value
Unknown

CVE-2021-3914

Disclosure Date: August 25, 2022 (last updated October 08, 2023)
It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.
Attacker Value
Unknown

CVE-2021-4178

Disclosure Date: August 24, 2022 (last updated October 08, 2023)
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.