VYPR

Maven package

com.netflix.conductor/conductor-core

pkg:maven/com.netflix.conductor/conductor-core

Vulnerabilities (1)

  • CVE-2020-9296Jun 16, 2020
    affected < 2.25.4fixed 2.25.4

    Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker can inject arbitrary data in the error message t