Show filters
129 Total Results
Displaying 41-50 of 129
Sort by:
Attacker Value
Unknown
CVE-2021-33192
Disclosure Date: July 05, 2021 (last updated February 22, 2025)
A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain page views. This issue affects Apache Jena Fuseki from version 2.0.0 to version 4.0.0 (inclusive).
0
Attacker Value
Unknown
CVE-2020-14340
Disclosure Date: June 02, 2021 (last updated February 22, 2025)
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
0
Attacker Value
Unknown
CVE-2020-10688
Disclosure Date: May 27, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
0
Attacker Value
Unknown
CVE-2021-20218
Disclosure Date: March 16, 2021 (last updated February 22, 2025)
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2
0
Attacker Value
Unknown
CVE-2020-27782
Disclosure Date: February 23, 2021 (last updated February 22, 2025)
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.
0
Attacker Value
Unknown
CVE-2020-10734
Disclosure Date: February 11, 2021 (last updated February 22, 2025)
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.
0
Attacker Value
Unknown
CVE-2020-1717
Disclosure Date: February 11, 2021 (last updated February 22, 2025)
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
0
Attacker Value
Unknown
CVE-2020-25689
Disclosure Date: November 02, 2020 (last updated February 22, 2025)
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.
0
Attacker Value
Unknown
CVE-2020-25644
Disclosure Date: October 06, 2020 (last updated February 22, 2025)
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
0
Attacker Value
Unknown
CVE-2020-10714
Disclosure Date: September 23, 2020 (last updated February 22, 2025)
A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
0