VYPR

Maven package

org.eclipse.birt/org.eclipse.birt.report.viewer

pkg:maven/org.eclipse.birt/org.eclipse.birt.report.viewer

Vulnerabilities (1)

  • CVE-2023-0100Mar 15, 2023
    affected >= 2.6.2, < 4.13fixed 4.13

    In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path for the report parameter (e.g. __report=http://xyz.com/report.rptdesign). If the host indicated in the __report parameter matched th