VYPR

apk package

chainguard/thingsboard-tb-node

pkg:apk/chainguard/thingsboard-tb-node

Vulnerabilities (167)

  • CVE-2024-34750HigJul 3, 2024
    affected < 3.7-r2fixed 3.7-r2

    Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn

  • CVE-2023-52428HigFeb 11, 2024
    affected < 3.7-r2fixed 3.7-r2

    In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

  • CVE-2023-3635MedJul 12, 2023
    affected < 3.7-r2fixed 3.7-r2

    GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

  • CVE-2023-1370HigMar 22, 2023
    affected < 3.7-r4fixed 3.7-r4

    [Json-smart](https://netplex.github.io/json-smart/) is a performance focused, JSON processor lib. When reaching a ‘[‘ or ‘{‘ character in the JSON input, the code parses an array or an object respectively. It was discovered that the code does not have any limit to the nesting o

  • CVE-2022-24329MedFeb 25, 2022
    affected < 3.7-r1fixed 3.7-r1

    In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.

  • CVE-2021-31684HigJun 1, 2021
    affected < 3.7-r4fixed 3.7-r4

    A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.

  • CVE-2020-29582MedFeb 3, 2021
    affected < 3.7-r1fixed 3.7-r1

    In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

Page 9 of 9