VYPR

rpm package

almalinux/guava

pkg:rpm/almalinux/guava

Vulnerabilities (3)

  • CVE-2025-67030HigMar 25, 2026
    affected < 33.3.0-5.module_el9.6.0+148+fb6dc857fixed 33.3.0-5.module_el9.6.0+148+fb6dc857

    Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

  • CVE-2022-29599CriMay 23, 2022
    affected < 28.1-3.module_el8.6.0+2786+d7c38b21fixed 28.1-3.module_el8.6.0+2786+d7c38b21

    In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

  • CVE-2020-13956MedDec 2, 2020
    affected < 28.1-3.module_el8.6.0+2786+d7c38b21fixed 28.1-3.module_el8.6.0+2786+d7c38b21

    Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.