VYPR

Maven package

org.apache.jackrabbit/jackrabbit-webapp

pkg:maven/org.apache.jackrabbit/jackrabbit-webapp

Vulnerabilities (1)

  • CVE-2023-37895CriJul 25, 2023
    affected >= 2.21.0, < 2.21.18fixed 2.21.18

    Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that c