VYPR

rpm package

almalinux/guava

pkg:rpm/almalinux/guava

Vulnerabilities (2)

  • CVE-2022-29599May 23, 2022
    affected < 28.1-3.module_el8.6.0+2786+d7c38b21fixed 28.1-3.module_el8.6.0+2786+d7c38b21

    In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

  • CVE-2020-13956Dec 2, 2020
    affected < 28.1-3.module_el8.6.0+2786+d7c38b21fixed 28.1-3.module_el8.6.0+2786+d7c38b21

    Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.