VYPR

Maven package

org.vivoweb/vitro-project

pkg:maven/org.vivoweb/vitro-project

Vulnerabilities (1)

  • CVE-2019-6986Jan 28, 2019
    affected < 1.11.0fixed 1.11.0

    SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as demonstrated by crafted use of FILTER%20regex in a /individual?uri= request.