Vulnerabilities
Vulnerable Software
Quarkus:  >> Quarkus  Security Vulnerabilities
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
CVSS Score
6.5
EPSS Score
0.012
Published
2020-07-06
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
CVSS Score
7.7
EPSS Score
0.025
Published
2020-06-04
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.
CVSS Score
7.5
EPSS Score
0.022
Published
2020-05-13
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
CVSS Score
5.3
EPSS Score
0.0
Published
2020-05-06
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.
CVSS Score
4.8
EPSS Score
0.001
Published
2020-04-06
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
CVSS Score
7.5
EPSS Score
0.022
Published
2019-12-12


Contact Us

Shodan ® - All rights reserved