VYPR

apk package

chainguard/cassandra-reaper

pkg:apk/chainguard/cassandra-reaper

Vulnerabilities (49)

  • CVE-2023-26048MedApr 18, 2023
    affected < 4.0.1-r1fixed 4.0.1-r1

    Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) that call `HttpServletRequest.getParameter()` or `HttpServletRequest.getParts()` may cause `OutOfMemoryError` when the client sends a

  • CVE-2021-46877HigMar 18, 2023
    affected < 4.0.1-r1fixed 4.0.1-r1

    jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.

  • CVE-2022-1471HigDec 1, 2022
    affected < 4.0.1-r1fixed 4.0.1-r1

    SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restric

  • CVE-2022-42004HigOct 2, 2022
    affected < 4.0.1-r1fixed 4.0.1-r1

    In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

  • CVE-2022-42003HigOct 2, 2022
    affected < 4.0.1-r1fixed 4.0.1-r1

    In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.

  • CVE-2020-36518HigMar 11, 2022
    affected < 4.0.1-r1fixed 4.0.1-r1

    jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

  • CVE-2021-28168MedApr 22, 2021
    affected < 4.0.1-r1fixed 4.0.1-r1

    Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents

  • CVE-2020-8908LowDec 10, 2020
    affected < 4.0.1-r1fixed 4.0.1-r1

    A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the

  • CVE-2015-0886Feb 28, 2015
    affected < 4.0.1-r1fixed 4.0.1-r1

    Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.

Page 3 of 3