Vulnerabilities
Vulnerable Software
Redhat:  >> Jboss Aerogear  Security Vulnerabilities
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless exceptions when those endpoints can't be reached or can slow the server down by purposefully wasting it's time with slow endpoints. Similarly, one can provide whatever HTTP end point they want. This turns the server into a DDOS vector or an anonymizer for the posting of malware and so on.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-07-01
Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.
CVSS Score
5.4
EPSS Score
0.002
Published
2022-07-01
JBoss AeroGear has reflected XSS via the password field
CVSS Score
6.1
EPSS Score
0.003
Published
2019-11-04


Contact Us

Shodan ® - All rights reserved