Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

108 advisories

Loading
Play Framework's Assets controller vulnerable to directory traversal High
CVE-2018-13864 was published for com.typesafe.play:play_2.12 (Maven) May 13, 2022
Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP Undertow High
CVE-2018-1048 was published for org.jboss.eap:wildfly-undertow (Maven) May 13, 2022
Path Traversal in Jenkins High
CVE-2018-1000194 was published for org.jenkins-ci.main:jenkins-core (Maven) May 13, 2022
Arbitrary filesystem write access from velocity. High
CVE-2022-24897 was published for org.xwiki.commons:xwiki-commons-velocity (Maven) Apr 28, 2022
kurt-r2c
Path traversal in the OWASP Enterprise Security API High
CVE-2022-23457 was published for org.owasp.esapi:esapi (Maven) Apr 27, 2022
JarLob
Path Traversal in Caucho Resin High
CVE-2021-44138 was published for com.caucho:resin (Maven) Apr 5, 2022
Path traversal in MCMS High
CVE-2021-46037 was published for net.mingsoft:ms-mcms (Maven) Feb 19, 2022
MCMS Arbitrary File Deletion vulnerability High
CVE-2021-46062 was published for net.mingsoft:ms-basic (Maven) Feb 19, 2022
Path Traversal in Crafter CMS Crafter Studio High
CVE-2017-15684 was published for org.craftercms:crafter-studio (Maven) Feb 9, 2022
Upload of file to arbitrary path in Apache Flink High
CVE-2020-17518 was published for org.apache.flink:flink-runtime (Maven) Feb 9, 2022
Path Traversal High
CVE-2020-14366 was published for org.keycloak:keycloak-parent (Maven) Feb 9, 2022
Path Traversal in Jenkins Warnings Next Generation Plugin High
CVE-2022-23107 was published for io.jenkins.plugins:warnings-ng (Maven) Jan 21, 2022
westonsteimel
Path Traversal in com.linecorp.armeria:armeria High
CVE-2021-43795 was published for com.linecorp.armeria:armeria (Maven) Dec 2, 2021
Directory traversal in Eclipse Mojarra High
CVE-2020-6950 was published for org.glassfish:mojarra-parent (Maven) Sep 1, 2021
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in micronaut-core High
CVE-2021-32769 was published for io.micronaut:micronaut-http-server-netty (Maven) Jul 26, 2021
strmik
Path Traversal in the Java Kubernetes Client High
CVE-2020-8570 was published for io.kubernetes:client-java (Maven) Jan 29, 2021
Path Traversal in Apache Flink High
CVE-2020-17519 was published for org.apache.flink:flink-runtime_2.11 (Maven) Jan 6, 2021
stephanmiehe
Directory Traversal in spring-boot-actuator-logview High
CVE-2021-21234 was published for eu.hinsch:spring-boot-actuator-logview (Maven) Jan 5, 2021
st0rmi
Directory traversal attack in Spring Cloud Config High
CVE-2020-5410 was published for org.springframework.cloud:spring-cloud-config-server (Maven) Jun 5, 2020
Path traversal attack on Windows platforms High
CVE-2019-0207 was published for org.apache.tapestry:tapestry-core (Maven) Nov 18, 2019
Path Traversal in DKPro Core High
CVE-2019-11082 was published for de.tudarmstadt.ukp.dkpro.core:de.tudarmstadt.ukp.dkpro.core.api.datasets-asl (Maven) May 29, 2019
Path Traversal in Apache Camel High
CVE-2019-0194 was published for org.apache.camel:camel-core (Maven) May 2, 2019
Improper Limitation of a Pathname ('Path Traversal') in org.apache.jspwiki:jspwiki-war High
CVE-2019-0225 was published for org.apache.jspwiki:jspwiki-war (Maven) Apr 8, 2019
Path Traversal in Hadoop High
CVE-2018-8009 was published for org.apache.hadoop:hadoop-main (Maven) Dec 21, 2018
MarkLee131
Directory Traversal vulnerability in Square Retrofit High
CVE-2018-1000850 was published for com.squareup.retrofit2:retrofit (Maven) Dec 21, 2018
ProTip! Advisories are also available from the GraphQL API