VYPR

Sw360

by Eclipse Sw360

CVEs (1)

  • CVE-2026-79653MedAug 27, 2026
    risk 0.32cvss epss

    In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enable.attachment.store.to.file.system, the attacker can manipulate the filename upon upload and can essentially cause arbitrary file path…