VYPR

Quarkus

by Quarkusio

Source repositories

CVEs (57)

  • CVE-2019-14900MedJul 6, 2020
    risk 0.35cvss 6.5epss 0.02

    A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an…

  • CVE-2020-10693MedMay 6, 2020
    risk 0.35cvss 5.3epss 0.02

    A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers…

  • CVE-2021-21295MedMar 9, 2021
    risk 0.33cvss 5.9epss 0.19

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request…

  • CVE-2021-21290MedFeb 8, 2021
    risk 0.33cvss 6.2epss 0.02

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file.…

  • CVE-2021-21409MedMar 30, 2021
    risk 0.32cvss 5.9epss 0.05

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request…

  • CVE-2025-66560MedJan 7, 2026
    risk 0.31cvss 5.9epss 0.00

    Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.27.2, and 3.20.5, a vulnerability exists in the HTTP layer of Quarkus REST related to response handling. When a response is being written, the framework waits…

  • CVE-2020-1728MedApr 6, 2020
    risk 0.31cvss 4.8epss 0.01

    A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their…

  • CVE-2024-1726MedApr 25, 2024
    risk 0.28cvss 5.3epss 0.01

    A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In certain configurations, if an attacker has…

  • CVE-2020-25724MedMay 26, 2021
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3…

  • CVE-2020-13956MedDec 2, 2020
    risk 0.28cvss 5.3epss 0.09

    Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

  • CVE-2021-29429MedApr 12, 2021
    risk 0.26cvss 4.0epss 0.00

    In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through…

  • CVE-2024-1979LowMar 13, 2024
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.

  • CVE-2020-8908LowDec 10, 2020
    risk 0.15cvss 3.3epss 0.01

    A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the…

  • CVE-2023-0481LowFeb 24, 2023
    risk 0.14cvss 3.3epss 0.00

    In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.

  • CVE-2021-28170MedMay 26, 2021
    risk 0.00cvss 5.3epss 0.02

    In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.

  • CVE-2021-29428HigApr 13, 2021
    risk 0.00cvss 8.8epss 0.01

    In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation from an attacker quickly…

  • CVE-2020-25633MedSep 18, 2020
    risk 0.00cvss 5.3epss 0.01

    A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the RESTEasy client call. The highest threat from this…

Page 3 of 3