VYPR

apk package

wolfi/druid

pkg:apk/wolfi/druid

Vulnerabilities (147)

  • CVE-2021-43797MedDec 9, 2021
    affected < 0fixed 0

    Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It shoul

  • CVE-2021-31684HigJun 1, 2021
    affected < 37.0.0-r14fixed 37.0.0-r14

    A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.

  • CVE-2021-21409MedMar 30, 2021
    affected < 0fixed 0

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smug

  • CVE-2021-21295MedMar 9, 2021
    affected < 0fixed 0

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smug

  • CVE-2021-21290MedFeb 8, 2021
    affected < 0fixed 0

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file.

  • CVE-2019-20445CriJan 29, 2020
    affected < 0fixed 0

    HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

  • CVE-2018-1320HigJan 7, 2019
    affected < 32.0.1-r1fixed 32.0.1-r1

    Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production

Page 8 of 8