VYPR

Dropwizard

by Dropwizard

CVEs (1)

  • CVE-2020-11002Apr 10, 2020
    risk 0.00cvss epss 0.01

    dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE)…