Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,435 advisories

Loading
Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19 Moderate
GHSA-c57f-4vp2-jqhm was published for com.vaadin:flow-server (Maven) May 6, 2021
Improper Input Validation in Spring Framework Moderate
CVE-2020-5421 was published for org.springframework:spring-framework-bom (Maven) Apr 30, 2021
joshbressers
Externally Controlled Reference to a Resource in Another Sphere and Confused Deputy in Spring Cloud Netflix Moderate
CVE-2020-5412 was published for org.springframework.cloud:spring-cloud-netflix (Maven) Apr 30, 2021
HTTP Request Smuggling in Undertow Moderate
CVE-2020-10687 was published for io.undertow:undertow-core (Maven) Apr 30, 2021
HTTP Request Smuggling in Undertow Moderate
CVE-2020-10719 was published for io.undertow:undertow-core (Maven) Apr 30, 2021
Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI Generator Maven plugin Moderate
CVE-2021-21429 was published for org.openapitools:openapi-generator-maven-plugin (Maven) Apr 29, 2021
JLLeitschuh
Path Traversal and Improper Input Validation in Apache Commons IO Moderate
CVE-2021-29425 was published for com.cosium.vet:vet (Maven) Apr 26, 2021
wtwhite jensdietrich
Local information disclosure via system temporary directory Moderate
CVE-2021-28168 was published for org.glassfish.jersey.core:jersey-common (Maven) Apr 23, 2021
JLLeitschuh
Observable Differences in Behavior to Error Inputs in Bouncy Castle Moderate
CVE-2020-26939 was published for org.bouncycastle:bc-fips (Maven) Apr 22, 2021
ebickle
Cross-site Scripting in GwtUpload Moderate
CVE-2020-9447 was published for com.googlecode.gwtupload:gwtupload (Maven) Apr 22, 2021
Cross-site scripting in Apache CXF Moderate
CVE-2020-13954 was published for org.apache.cxf:apache-cxf (Maven) Apr 22, 2021
Remote Code Execution and download tracking in Mintegral SDK Moderate
CVE-2020-7744 was published for com.mintegral.msdk:alphab (Maven) Apr 22, 2021
Missing Authentication for Critical Function in Apache Calcite Moderate
CVE-2020-13955 was published for org.apache.calcite:calcite-core (Maven) Apr 22, 2021
Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19 Moderate
GHSA-6hgr-2g6q-3rmc was published for com.vaadin:flow-client (Maven) Apr 22, 2021
tdunlap607
Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19 Moderate
CVE-2021-31408 was published for com.vaadin:vaadin-bom (Maven) Apr 22, 2021
Reflected cross-site scripting in default RouteNotFoundError view in Vaadin 10 and 11-13 Moderate
CVE-2019-25027 was published for com.vaadin:flow-server (Maven) Apr 19, 2021
Directory traversal in development mode handler in Vaadin 14 and 15-17 Moderate
CVE-2020-36321 was published for com.vaadin:flow-server (Maven) Apr 19, 2021
Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18 Moderate
CVE-2021-31404 was published for com.vaadin:flow-server (Maven) Apr 19, 2021
Timing side channel vulnerability in UIDL request handler in Vaadin 7 and 8 Moderate
CVE-2021-31403 was published for com.vaadin:vaadin-bom (Maven) Apr 19, 2021
Timing side channel vulnerability in endpoint request handler in Vaadin 15-19 Moderate
CVE-2021-31406 was published for com.vaadin:flow-server (Maven) Apr 19, 2021
Stored cross-site scripting in Grid component in Vaadin 7 and 8 Moderate
CVE-2019-25028 was published for com.vaadin:vaadin-bom (Maven) Apr 19, 2021
Reflected cross-site scripting in default RouteNotFoundError view in Vaadin 10 and 11-13 Moderate
GHSA-jqj4-r483-4gvr was published for com.vaadin:vaadin-bom (Maven) Apr 19, 2021
Directory traversal in development mode handler in Vaadin 14 and 15-17 Moderate
GHSA-82mf-mmh7-hxp5 was published for com.vaadin:vaadin-bom (Maven) Apr 19, 2021
Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18 Moderate
GHSA-c6c4-7x48-4cqp was published for com.vaadin:vaadin-bom (Maven) Apr 19, 2021
Timing side channel vulnerability in endpoint request handler in Vaadin 15-19 Moderate
GHSA-9h6g-6mxg-vvp4 was published for com.vaadin:vaadin-bom (Maven) Apr 19, 2021
xhlika
ProTip! Advisories are also available from the GraphQL API