VYPR

rpm package

almalinux/cdi-api

pkg:rpm/almalinux/cdi-api

Vulnerabilities (4)

  • CVE-2025-48734May 28, 2025
    affected < 1.2-8.module_el8.0.0+6004+2fc32706fixed 1.2-8.module_el8.0.0+6004+2fc32706

    Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no

  • CVE-2022-29599May 23, 2022
    affected < 2.0.1-3.module_el8.6.0+2786+d7c38b21fixed 2.0.1-3.module_el8.6.0+2786+d7c38b21

    In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

  • CVE-2020-13956Dec 2, 2020
    affected < 2.0.1-3.module_el8.6.0+2786+d7c38b21fixed 2.0.1-3.module_el8.6.0+2786+d7c38b21

    Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

  • CVE-2019-10086Aug 20, 2019
    affected < 1.2-8.module_el8.0.0+6004+2fc32706fixed 1.2-8.module_el8.0.0+6004+2fc32706

    In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the Prop