Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54fx-gm74-q676

Опубликовано: 18 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4

Описание

Permissions bypass in SmallRye

A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2

Пакеты

Наименование

io.smallrye.config:smallrye-config

maven
Затронутые версииВерсия исправления

< 1.6.2

1.6.2

EPSS

Процентиль: 11%
0.00038
Низкий

4 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4
redhat
почти 6 лет назад

A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2

CVSS3: 4.4
nvd
больше 4 лет назад

A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2

EPSS

Процентиль: 11%
0.00038
Низкий

4 Medium

CVSS3

Дефекты

CWE-863