Maven package
org.apache.jackrabbit/jackrabbit-standalone
pkg:maven/org.apache.jackrabbit/jackrabbit-standalone
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-37895 | Cri | 9.8 | >= 2.21.0, < 2.21.18 | 2.21.18 | Jul 25, 2023 | Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that c |
- affected >= 2.21.0, < 2.21.18fixed 2.21.18
Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that c