{"grype_matches":[{"artifact":{"id":"d4c86865da6ad268","cpes":["cpe:2.3:a:org.springframework:spring-beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-beans:spring-beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-beans:spring_beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_beans:spring-beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_beans:spring_beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_beans:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-beans","purl":"pkg:maven/org.springframework/spring-beans@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-beans-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-beans","archiveDigests":[{"value":"03ae97694618c59e6af695a15e54fabb7e319776","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-beans-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.20.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-36p3-wjmg-h94x","versionConstraint":"<5.2.20.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-beans","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-36p3-wjmg-h94x","fix":{"state":"fixed","versions":["5.2.20.RELEASE"],"available":[{"date":"2022-12-16","kind":"first-observed","version":"5.2.20.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"risk":98.70000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965","https://github.com/spring-projects/spring-framework/commit/002546b3e4b8d791ea6acccb81eb3168f51abb15","https://github.com/spring-projects/spring-boot/releases/tag/v2.5.12","https://github.com/spring-projects/spring-boot/releases/tag/v2.6.6","https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE","https://github.com/spring-projects/spring-framework/releases/tag/v5.3.18","https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement","https://tanzu.vmware.com/security/cve-2022-22965","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-36p3-wjmg-h94x","description":"Remote Code Execution in Spring Framework","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2022-22965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"urls":["http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tanzu.vmware.com/security/cve-2022-22965","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22965","description":"A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"38d69bb5d3f4bcbc","cpes":["cpe:2.3:a:org.springframework.boot:spring-boot-starter-web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.boot:spring_boot_starter_web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter-web:spring-boot-starter-web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter-web:spring_boot_starter_web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter_web:spring-boot-starter-web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter_web:spring_boot_starter_web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter:spring-boot-starter-web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter:spring_boot_starter_web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter:spring-boot-starter-web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter:spring_boot_starter_web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-boot-starter-web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_boot_starter_web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot:spring-boot-starter-web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot:spring_boot_starter_web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot:spring-boot-starter-web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot:spring_boot_starter_web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-boot-starter-web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_boot_starter_web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.boot:boot:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:boot:spring-boot-starter-web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:boot:spring_boot_starter_web:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter-web:boot:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter_web:boot:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot-starter:boot:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot_starter:boot:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:boot:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-boot:boot:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_boot:boot:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:boot:2.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:boot:boot:2.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-boot-starter-web","purl":"pkg:maven/org.springframework.boot/spring-boot-starter-web@2.2.0.RELEASE","type":"java-archive","version":"2.2.0.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.boot","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-boot-starter-web-2.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-boot-starter-web","archiveDigests":[{"value":"a63661766218b06e540e58f7f3d4cf64278af92c","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-boot-starter-web-2.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-36p3-wjmg-h94x","versionConstraint":"<2.5.12 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.boot:spring-boot-starter-web","version":"2.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-36p3-wjmg-h94x","fix":{"state":"fixed","versions":["2.5.12"],"available":[{"date":"2022-04-01","kind":"first-observed","version":"2.5.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"risk":98.70000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965","https://github.com/spring-projects/spring-framework/commit/002546b3e4b8d791ea6acccb81eb3168f51abb15","https://github.com/spring-projects/spring-boot/releases/tag/v2.5.12","https://github.com/spring-projects/spring-boot/releases/tag/v2.6.6","https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE","https://github.com/spring-projects/spring-framework/releases/tag/v5.3.18","https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement","https://tanzu.vmware.com/security/cve-2022-22965","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-36p3-wjmg-h94x","description":"Remote Code Execution in Spring Framework","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2022-22965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"urls":["http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tanzu.vmware.com/security/cve-2022-22965","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22965","description":"A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"3f92c454a30427fb","cpes":["cpe:2.3:a:org.springframework:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-webmvc","purl":"pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-webmvc-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-webmvc","archiveDigests":[{"value":"652abc943904d67504dc822197868cafaa5e56b5","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-webmvc-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.20.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-36p3-wjmg-h94x","versionConstraint":"<5.2.20.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-webmvc","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-36p3-wjmg-h94x","fix":{"state":"fixed","versions":["5.2.20.RELEASE"],"available":[{"date":"2022-12-16","kind":"first-observed","version":"5.2.20.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"risk":98.70000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965","https://github.com/spring-projects/spring-framework/commit/002546b3e4b8d791ea6acccb81eb3168f51abb15","https://github.com/spring-projects/spring-boot/releases/tag/v2.5.12","https://github.com/spring-projects/spring-boot/releases/tag/v2.6.6","https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE","https://github.com/spring-projects/spring-framework/releases/tag/v5.3.18","https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement","https://tanzu.vmware.com/security/cve-2022-22965","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-36p3-wjmg-h94x","description":"Remote Code Execution in Spring Framework","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2022-22965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22965","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22965","date":"2026-10-08","epss":0.99638,"percentile":0.99949}],"urls":["http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html","http://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.html","https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005","https://tanzu.vmware.com/security/cve-2022-22965","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.kb.cert.org/vuls/id/970766","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22965","description":"A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.","knownExploited":[{"cve":"CVE-2022-22965","cwes":["CWE-94"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22965"],"dueDate":"2022-04-25","product":"Spring Framework","dateAdded":"2022-04-04","vendorProject":"VMware","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c9hw-wf7x-jp9j","versionConstraint":">=9.0.0,<9.0.31 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c9hw-wf7x-jp9j","fix":{"state":"fixed","versions":["9.0.31"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"9.0.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1938","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1938","date":"2026-10-08","epss":0.9927,"percentile":0.99937}],"risk":98.70000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-1938","https://lists.apache.org/thread.html/r089dc67c0358a1556dd279c762c74f32d7a254a54836b7ee2d839d8e@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r43faacf64570b1d9a4bada407a5af3b2738b0c007b905f1b6b608c65@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4afa11e0464408e68f0e9560e90b185749363a66398b1491254f7864@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4f86cb260196e5cfcbbe782822c225ddcc70f54560f14a8f11c6926f@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r549b43509e387a42656f0641fa311bf27c127c244fe02007d5b8d6f6@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r5e2f1201b92ee05a0527cfc076a81ea0c270be299b87895c0ddbe02b@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r61f280a76902b594692f0b24a1dbf647bb5a4c197b9395e9a6796e7c@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6a5633cad1b560a1e51f5b425f02918bdf30e090fdf18c5f7c2617eb@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r74328b178f9f37fe759dffbc9c1f2793e66d79d7a8a20d3836551794@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r75113652e46c4dee687236510649acfb70d2c63e074152049c3f399d@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r772335e6851ad33ddb076218fa4ff70de1bf398d5b43e2ddf0130e5d@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r856cdd87eda7af40b50278d6de80ee4b42d63adeb433a34a7bdaf9db@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r9f119d9ce9239114022e13dbfe385b3de7c972f24f05d6dbd35c1a2f@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad36ec6a1ffc9e43266b030c22ceeea569243555d34fb4187ff08522@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb2fc890bef23cbc7f343900005fe1edd3b091cf18dada455580258f9@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rbdb1d2b651a3728f0ceba9e0853575b6f90296a94a71836a15f7364a@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rcd5cd301e9e7e39f939baf2f5d58704750be07a5e2d3393e40ca7194@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rce2af55f6e144ffcdc025f997eddceb315dfbc0b230e3d750a7f7425@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rd0774c95699d5aeb5e16e9a600fb2ea296e81175e30a62094e27e3e7@%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/re5eecbe5bf967439bafeeaa85987b3a43f0e6efe06b6976ee768cde2@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf26663f42e7f1a1d1cac732469fb5e92c89908a48b61ec546dbb79ca@%3Cbugs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rf992c5adf376294af31378a70aa8a158388a41d7039668821be28df3@%3Ccommits.tomee.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://security.gentoo.org/glsa/202003-43","https://www.debian.org/security/2020/dsa-4673","https://www.debian.org/security/2020/dsa-4680","http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00002.html","http://support.blackberry.com/kb/articleDetail?articleNumber=000062739","https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed@%3Cdev.tomcat.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r92d78655c068d0bc991d1edbdfb24f9c5134603e647cade1113d4e0a@%3Cusers.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r47caef01f663106c2bb81d116b8380d62beac9e543dd3f3bc2c2beda@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r57f5e4ced436ace518a9e222fabe27fb785f09f5bf974814cc48ca97@%3Ccommits.tomee.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/re5eecbe5bf967439bafeeaa85987b3a43f0e6efe06b6976ee768cde2%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd0774c95699d5aeb5e16e9a600fb2ea296e81175e30a62094e27e3e7%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rce2af55f6e144ffcdc025f997eddceb315dfbc0b230e3d750a7f7425%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rcd5cd301e9e7e39f939baf2f5d58704750be07a5e2d3393e40ca7194%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rbdb1d2b651a3728f0ceba9e0853575b6f90296a94a71836a15f7364a%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rb2fc890bef23cbc7f343900005fe1edd3b091cf18dada455580258f9%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad36ec6a1ffc9e43266b030c22ceeea569243555d34fb4187ff08522%40%3Cnotifications.ofbiz.apache.org%3E","https://security.netapp.com/advisory/ntap-20200226-0002","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L46WJIV6UV3FWA5O5YEY6XLA73RYD53B","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K3IPNHCKFVUKSHDTM45UL4Q765EHHTFG","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2XFLQB3O5QVP4ZBIPVIXBEZV7F2R7ZMS","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L46WJIV6UV3FWA5O5YEY6XLA73RYD53B","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3IPNHCKFVUKSHDTM45UL4Q765EHHTFG","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2XFLQB3O5QVP4ZBIPVIXBEZV7F2R7ZMS","https://lists.apache.org/thread.html/rf992c5adf376294af31378a70aa8a158388a41d7039668821be28df3%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf26663f42e7f1a1d1cac732469fb5e92c89908a48b61ec546dbb79ca%40%3Cbugs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r5e2f1201b92ee05a0527cfc076a81ea0c270be299b87895c0ddbe02b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r57f5e4ced436ace518a9e222fabe27fb785f09f5bf974814cc48ca97%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r549b43509e387a42656f0641fa311bf27c127c244fe02007d5b8d6f6%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4f86cb260196e5cfcbbe782822c225ddcc70f54560f14a8f11c6926f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4afa11e0464408e68f0e9560e90b185749363a66398b1491254f7864%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r47caef01f663106c2bb81d116b8380d62beac9e543dd3f3bc2c2beda%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r43faacf64570b1d9a4bada407a5af3b2738b0c007b905f1b6b608c65%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r089dc67c0358a1556dd279c762c74f32d7a254a54836b7ee2d839d8e%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r9f119d9ce9239114022e13dbfe385b3de7c972f24f05d6dbd35c1a2f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r92d78655c068d0bc991d1edbdfb24f9c5134603e647cade1113d4e0a%40%3Cusers.tomee.apache.org%3E","https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r856cdd87eda7af40b50278d6de80ee4b42d63adeb433a34a7bdaf9db%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r772335e6851ad33ddb076218fa4ff70de1bf398d5b43e2ddf0130e5d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r75113652e46c4dee687236510649acfb70d2c63e074152049c3f399d%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r74328b178f9f37fe759dffbc9c1f2793e66d79d7a8a20d3836551794%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r6a5633cad1b560a1e51f5b425f02918bdf30e090fdf18c5f7c2617eb%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r61f280a76902b594692f0b24a1dbf647bb5a4c197b9395e9a6796e7c%40%3Cusers.tomcat.apache.org%3E","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1938"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c9hw-wf7x-jp9j","description":"Improper Privilege Management in Tomcat","knownExploited":[{"cve":"CVE-2020-1938","urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-1938"],"dueDate":"2022-03-17","product":"Tomcat","dateAdded":"2022-03-03","vendorProject":"Apache","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2020-1938","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1938","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1938","date":"2026-10-08","epss":0.9927,"percentile":0.99937}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00002.html","http://support.blackberry.com/kb/articleDetail?articleNumber=000062739","https://lists.apache.org/thread.html/r089dc67c0358a1556dd279c762c74f32d7a254a54836b7ee2d839d8e%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r43faacf64570b1d9a4bada407a5af3b2738b0c007b905f1b6b608c65%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r47caef01f663106c2bb81d116b8380d62beac9e543dd3f3bc2c2beda%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r4afa11e0464408e68f0e9560e90b185749363a66398b1491254f7864%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4f86cb260196e5cfcbbe782822c225ddcc70f54560f14a8f11c6926f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r549b43509e387a42656f0641fa311bf27c127c244fe02007d5b8d6f6%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r57f5e4ced436ace518a9e222fabe27fb785f09f5bf974814cc48ca97%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r5e2f1201b92ee05a0527cfc076a81ea0c270be299b87895c0ddbe02b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r61f280a76902b594692f0b24a1dbf647bb5a4c197b9395e9a6796e7c%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6a5633cad1b560a1e51f5b425f02918bdf30e090fdf18c5f7c2617eb%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r74328b178f9f37fe759dffbc9c1f2793e66d79d7a8a20d3836551794%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r75113652e46c4dee687236510649acfb70d2c63e074152049c3f399d%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r772335e6851ad33ddb076218fa4ff70de1bf398d5b43e2ddf0130e5d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r856cdd87eda7af40b50278d6de80ee4b42d63adeb433a34a7bdaf9db%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r92d78655c068d0bc991d1edbdfb24f9c5134603e647cade1113d4e0a%40%3Cusers.tomee.apache.org%3E","https://lists.apache.org/thread.html/r9f119d9ce9239114022e13dbfe385b3de7c972f24f05d6dbd35c1a2f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rad36ec6a1ffc9e43266b030c22ceeea569243555d34fb4187ff08522%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb2fc890bef23cbc7f343900005fe1edd3b091cf18dada455580258f9%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rbdb1d2b651a3728f0ceba9e0853575b6f90296a94a71836a15f7364a%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rcd5cd301e9e7e39f939baf2f5d58704750be07a5e2d3393e40ca7194%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rce2af55f6e144ffcdc025f997eddceb315dfbc0b230e3d750a7f7425%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rd0774c95699d5aeb5e16e9a600fb2ea296e81175e30a62094e27e3e7%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/re5eecbe5bf967439bafeeaa85987b3a43f0e6efe06b6976ee768cde2%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf26663f42e7f1a1d1cac732469fb5e92c89908a48b61ec546dbb79ca%40%3Cbugs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rf992c5adf376294af31378a70aa8a158388a41d7039668821be28df3%40%3Ccommits.tomee.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2XFLQB3O5QVP4ZBIPVIXBEZV7F2R7ZMS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3IPNHCKFVUKSHDTM45UL4Q765EHHTFG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L46WJIV6UV3FWA5O5YEY6XLA73RYD53B/","https://security.gentoo.org/glsa/202003-43","https://security.netapp.com/advisory/ntap-20200226-0002/","https://www.debian.org/security/2020/dsa-4673","https://www.debian.org/security/2020/dsa-4680","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1938"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1938","description":"When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.","knownExploited":[{"cve":"CVE-2020-1938","urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-1938"],"dueDate":"2022-03-17","product":"Tomcat","dateAdded":"2022-03-03","vendorProject":"Apache","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.99"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-83qj-6fr2-vhqg","versionConstraint":">=9.0.0.M1,<9.0.99 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-83qj-6fr2-vhqg","fix":{"state":"fixed","versions":["9.0.99"],"available":[{"date":"2025-03-18","kind":"first-observed","version":"9.0.99"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-24813","cwe":"CWE-44","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-24813","cwe":"CWE-502","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-24813","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-24813","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-24813","date":"2026-10-08","epss":0.99927,"percentile":0.99969}],"risk":97.125,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-24813","https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq","http://www.openwall.com/lists/oss-security/2025/03/10/5","https://github.com/apache/tomcat/commit/0a668e0c27f2b7ca0cc7c6eea32253b9b5ecb29c","https://github.com/apache/tomcat/commit/eb61aade8f8daccaecabf07d428b877975622f72","https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc","https://github.com/absholi7ly/POC-CVE-2025-24813/blob/main/README.md","https://www.vicarius.io/vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce","https://www.vicarius.io/vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce","https://security.netapp.com/advisory/ntap-20250321-0001","https://lists.debian.org/debian-lts-announce/2025/04/msg00003.html","https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-detect-vulnerability","https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerability","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24813"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-83qj-6fr2-vhqg","description":"Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT","knownExploited":[{"cve":"CVE-2025-24813","cwes":["CWE-44","CWE-502"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-24813"],"notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq","dueDate":"2025-04-22","product":"Tomcat","dateAdded":"2025-04-01","vendorProject":"Apache","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2025-24813","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-24813","cwe":"CWE-44","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-24813","cwe":"CWE-502","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-24813","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-24813","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-24813","date":"2026-10-08","epss":0.99927,"percentile":0.99969}],"urls":["https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq","http://www.openwall.com/lists/oss-security/2025/03/10/5","https://lists.debian.org/debian-lts-announce/2025/04/msg00003.html","https://security.netapp.com/advisory/ntap-20250321-0001/","https://www.vicarius.io/vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce","https://www.vicarius.io/vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce","https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-detect-vulnerability","https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerability","https://github.com/absholi7ly/POC-CVE-2025-24813/blob/main/README.md","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24813"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-24813","description":"Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nIf all of the following were true, a malicious user was able to view       security sensitive files and/or inject content into those files:\n- writes enabled for the default servlet (disabled by default)\n- support for partial PUT (enabled by default)\n- a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads\n- attacker knowledge of the names of security sensitive files being uploaded\n- the security sensitive files also being uploaded via partial PUT\n\nIf all of the following were true, a malicious user was able to       perform remote code execution:\n- writes enabled for the default servlet (disabled by default)\n- support for partial PUT (enabled by default)\n- application was using Tomcat's file based session persistence with the default storage location\n- application included a library that may be leveraged in a deserialization attack\n\nUsers are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.","knownExploited":[{"cve":"CVE-2025-24813","cwes":["CWE-44","CWE-502"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-24813"],"notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq","dueDate":"2025-04-22","product":"Tomcat","dateAdded":"2025-04-01","vendorProject":"Apache","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"839771142f972cee","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/ubuntu/libnghttp2-14@1.30.0-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=nghttp2","type":"deb","version":"1.30.0-1ubuntu1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","SIL-OFL-1.1","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-44487","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nghttp2","version":"1.30.0-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-44487","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-44487","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-44487","date":"2026-10-08","epss":0.99999,"percentile":0.99998}],"risk":78.75000000000001,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-44487","knownExploited":[{"cve":"CVE-2023-44487","cwes":["CWE-400"],"urls":["https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://nvd.nist.gov/vuln/detail/CVE-2023-44487"],"notes":"This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","dueDate":"2023-10-31","product":"HTTP/2","dateAdded":"2023-10-10","vendorProject":"IETF","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2023-44487","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-44487","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-44487","date":"2026-10-08","epss":0.99999,"percentile":0.99998}],"urls":["http://www.openwall.com/lists/oss-security/2023/10/10/6","http://www.openwall.com/lists/oss-security/2023/10/10/7","http://www.openwall.com/lists/oss-security/2023/10/13/4","http://www.openwall.com/lists/oss-security/2023/10/13/9","http://www.openwall.com/lists/oss-security/2023/10/18/4","http://www.openwall.com/lists/oss-security/2023/10/18/8","http://www.openwall.com/lists/oss-security/2023/10/19/6","http://www.openwall.com/lists/oss-security/2023/10/20/8","https://access.redhat.com/security/cve/cve-2023-44487","https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/","https://aws.amazon.com/security/security-bulletins/AWS-2023-011/","https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/","https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/","https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack","https://blog.vespa.ai/cve-2023-44487/","https://bugzilla.proxmox.com/show_bug.cgi?id=4988","https://bugzilla.redhat.com/show_bug.cgi?id=2242803","https://bugzilla.suse.com/show_bug.cgi?id=1216123","https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9","https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/","https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack","https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125","https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715","https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve","https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764","https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088","https://github.com/Azure/AKS/issues/3947","https://github.com/Kong/kong/discussions/11741","https://github.com/advisories/GHSA-qppj-fm5r-hxr3","https://github.com/advisories/GHSA-vx74-f528-fxqg","https://github.com/advisories/GHSA-xpw8-rcwv-8f8p","https://github.com/akka/akka-http/issues/4323","https://github.com/alibaba/tengine/issues/1872","https://github.com/apache/apisix/issues/10320","https://github.com/apache/httpd-site/pull/10","https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113","https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2","https://github.com/apache/trafficserver/pull/10564","https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487","https://github.com/bcdannyboy/CVE-2023-44487","https://github.com/caddyserver/caddy/issues/5877","https://github.com/caddyserver/caddy/releases/tag/v2.7.5","https://github.com/dotnet/announcements/issues/277","https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73","https://github.com/eclipse/jetty.project/issues/10679","https://github.com/envoyproxy/envoy/pull/30055","https://github.com/etcd-io/etcd/issues/16740","https://github.com/facebook/proxygen/pull/466","https://github.com/golang/go/issues/63417","https://github.com/grpc/grpc-go/pull/6703","https://github.com/grpc/grpc/releases/tag/v1.59.2","https://github.com/h2o/h2o/pull/3291","https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf","https://github.com/haproxy/haproxy/issues/2312","https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244","https://github.com/junkurihara/rust-rpxy/issues/97","https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1","https://github.com/kazu-yamamoto/http2/issues/93","https://github.com/kubernetes/kubernetes/pull/121120","https://github.com/line/armeria/pull/5232","https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632","https://github.com/micrictor/http2-rst-stream","https://github.com/microsoft/CBL-Mariner/pull/6381","https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61","https://github.com/nghttp2/nghttp2/pull/1961","https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0","https://github.com/ninenines/cowboy/issues/1615","https://github.com/nodejs/node/pull/50121","https://github.com/openresty/openresty/issues/930","https://github.com/opensearch-project/data-prepper/issues/3474","https://github.com/oqtane/oqtane.framework/discussions/3367","https://github.com/projectcontour/contour/pull/5826","https://github.com/tempesta-tech/tempesta/issues/1986","https://github.com/varnishcache/varnish-cache/issues/3996","https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo","https://istio.io/latest/news/security/istio-security-2023-004/","https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/","https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html","https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html","https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/","https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html","https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html","https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html","https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487","https://my.f5.com/manage/s/article/K000137106","https://netty.io/news/2023/10/10/4-1-100-Final.html","https://news.ycombinator.com/item?id=37830987","https://news.ycombinator.com/item?id=37830998","https://news.ycombinator.com/item?id=37831062","https://news.ycombinator.com/item?id=37837043","https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/","https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected","https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20231016-0001/","https://security.netapp.com/advisory/ntap-20240426-0007/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://security.netapp.com/advisory/ntap-20240621-0007/","https://security.paloaltonetworks.com/CVE-2023-44487","https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14","https://ubuntu.com/security/CVE-2023-44487","https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/","https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522","https://www.debian.org/security/2023/dsa-5540","https://www.debian.org/security/2023/dsa-5549","https://www.debian.org/security/2023/dsa-5558","https://www.debian.org/security/2023/dsa-5570","https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487","https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/","https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/","https://www.openwall.com/lists/oss-security/2023/10/10/6","https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack","https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/","http://www.openwall.com/lists/oss-security/2025/08/13/6","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/","https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-341067.html","https://cert-portal.siemens.com/productcert/html/ssa-784301.html","https://cert-portal.siemens.com/productcert/html/ssa-832273.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487","https://github.com/envoyproxy/envoy/security/advisories/GHSA-jhv4-f7mr-xx76","https://github.com/kubernetes/ingress-nginx/blob/4b5c5efe2508dc915a48c54de7f23912ff2ec695/changelog/controller-1.9.3.md?plain=1#L15","https://varnish-cache.org/releases/rel6.0.12.html#rel6-0-12","https://varnish-cache.org/releases/rel7.3.1.html#rel7-3-1","https://varnish-cache.org/releases/rel7.4.2.html#rel7-4-2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-44487","description":"The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.","knownExploited":[{"cve":"CVE-2023-44487","cwes":["CWE-400"],"urls":["https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://nvd.nist.gov/vuln/detail/CVE-2023-44487"],"notes":"This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","dueDate":"2023-10-31","product":"HTTP/2","dateAdded":"2023-10-10","vendorProject":"IETF","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"1aef213d2b0dcd29","cpes":["cpe:2.3:a:libfreetype6:libfreetype6:2.8.1-2ubuntu2:*:*:*:*:*:*:*"],"name":"libfreetype6","purl":"pkg:deb/ubuntu/libfreetype6@2.8.1-2ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=freetype","type":"deb","version":"2.8.1-2ubuntu2","language":"","licenses":["BSD-2-Clause","BSD-3-Clause","Catharon-OSL","FTL","GPL-2","GPL-2+","GZip","OpenGroup-BSD-like"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfreetype6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libfreetype6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"freetype"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.1-2ubuntu2.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15999","versionConstraint":"< 2.8.1-2ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"freetype","version":"2.8.1-2ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-15999","fix":{"state":"fixed","versions":["2.8.1-2ubuntu2.1"],"available":[{"date":"2020-10-20","kind":"advisory","version":"2.8.1-2ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-15999","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15999","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15999","date":"2026-10-08","epss":0.63894,"percentile":0.99206}],"risk":78.75000000000001,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-15999","knownExploited":[{"cve":"CVE-2020-15999","cwes":["CWE-787"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-15999"],"dueDate":"2021-11-17","product":"Chrome FreeType","dateAdded":"2021-11-03","vendorProject":"Google","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2020-15999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15999","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15999","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15999","date":"2026-10-08","epss":0.63894,"percentile":0.99206}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html","http://seclists.org/fulldisclosure/2020/Nov/33","https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html","https://crbug.com/1139963","https://googleprojectzero.blogspot.com/p/rca-cve-2020-15999.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J3QVIGAAJ4D62YEJAJJWMCCBCOQ6TVL7/","https://security.gentoo.org/glsa/202011-12","https://security.gentoo.org/glsa/202012-04","https://security.gentoo.org/glsa/202401-19","https://www.debian.org/security/2021/dsa-4824","https://security.netapp.com/advisory/ntap-20240812-0001/","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-15999"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15999","description":"Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.","knownExploited":[{"cve":"CVE-2020-15999","cwes":["CWE-787"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-15999"],"dueDate":"2021-11-17","product":"Chrome FreeType","dateAdded":"2021-11-03","vendorProject":"Google","requiredAction":"Apply updates per vendor instructions.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"2a658e44e9176fca","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.25:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.25","type":"java-archive","version":"1.25","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/snakeyaml-1.25.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"8b6e01ef661d8378ae6dd7b511a7f2a33fae1421","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/snakeyaml-1.25.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mjmj-j48q-9wg2","versionConstraint":"<=1.33 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.25"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mjmj-j48q-9wg2","fix":{"state":"fixed","versions":["2.0"],"available":[{"date":"2023-03-05","kind":"first-observed","version":"2.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1471","cwe":"CWE-20","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-1471","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1471","date":"2026-10-08","epss":0.99569,"percentile":0.99946}],"risk":78.65951,"urls":["https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2","https://nvd.nist.gov/vuln/detail/CVE-2022-1471","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64581479","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64634374","https://bitbucket.org/snakeyaml/snakeyaml/wiki/CVE-2022-1471","https://github.com/mbechler/marshalsec","https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true","https://bitbucket.org/snakeyaml/snakeyaml/commits/5014df1a36f50aca54405bb8433bc99a8847f758","https://bitbucket.org/snakeyaml/snakeyaml/commits/acc44099f5f4af26ff86b4e4e4cc1c874e2dc5c4","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64876314","https://groups.google.com/g/kubernetes-security-announce/c/mwrakFaEdnc","http://packetstormsecurity.com/files/175095/PyTorch-Model-Server-Registration-Deserialization-Remote-Code-Execution.html","http://www.openwall.com/lists/oss-security/2023/11/19/1","https://security.netapp.com/advisory/ntap-20230818-0015","https://security.netapp.com/advisory/ntap-20240621-0006","https://snyk.io/blog/unsafe-deserialization-snakeyaml-java-cve-2022-1471","https://confluence.atlassian.com/security/cve-2022-1471-snakeyaml-library-rce-vulnerability-in-multiple-products-1296171009.html","https://infosecwriteups.com/%EF%B8%8F-inside-the-160-comment-fight-to-fix-snakeyamls-rce-default-1a20c5ca4d4c"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mjmj-j48q-9wg2","description":"SnakeYaml Constructor Deserialization Remote Code Execution"},"relatedVulnerabilities":[{"id":"CVE-2022-1471","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1471","cwe":"CWE-20","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-1471","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1471","date":"2026-10-08","epss":0.99569,"percentile":0.99946}],"urls":["http://packetstormsecurity.com/files/175095/PyTorch-Model-Server-Registration-Deserialization-Remote-Code-Execution.html","http://www.openwall.com/lists/oss-security/2023/11/19/1","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64581479","https://confluence.atlassian.com/security/cve-2022-1471-snakeyaml-library-rce-vulnerability-in-multiple-products-1296171009.html","https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2","https://github.com/mbechler/marshalsec","https://groups.google.com/g/kubernetes-security-announce/c/mwrakFaEdnc","https://infosecwriteups.com/%EF%B8%8F-inside-the-160-comment-fight-to-fix-snakeyamls-rce-default-1a20c5ca4d4c","https://security.netapp.com/advisory/ntap-20230818-0015/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1471","description":"SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond."}]},{"artifact":{"id":"958287065b0f2a45","cpes":["cpe:2.3:a:org.h2.util.DbDriverActivator:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:DbDriverActivator:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:org.h2.util.DbDriverActivator:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:com.h2database:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:org.h2.util.DbDriverActivator:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2database:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:DbDriverActivator:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:util:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:DbDriverActivator:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:com.h2database:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:com.h2database:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2database:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2database:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:util:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:util:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2:h2:1.4.200:*:*:*:*:*:*:*"],"name":"h2","purl":"pkg:maven/com.h2database/h2@1.4.200","type":"java-archive","version":"1.4.200","language":"java","licenses":["https://h2database.com/html/license.html"],"metadata":{"pomGroupID":"com.h2database","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/h2-1.4.200.jar","manifestName":"","pomArtifactID":"h2","archiveDigests":[{"value":"f7533fe7cb8e99c87a43d325a77b4b678ad9031a","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/h2-1.4.200.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.0.206"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h376-j262-vhq6","versionConstraint":">=1.1.100,<2.0.206 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.h2database:h2","version":"1.4.200"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h376-j262-vhq6","fix":{"state":"fixed","versions":["2.0.206"],"available":[{"date":"2022-01-07","kind":"first-observed","version":"2.0.206"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-42392","cwe":"CWE-502","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2021-42392","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-42392","date":"2026-10-08","epss":0.83176,"percentile":0.99672}],"risk":78.18544,"urls":["https://github.com/h2database/h2database/security/advisories/GHSA-h376-j262-vhq6","https://github.com/h2database/h2database/releases/tag/version-2.0.206","https://nvd.nist.gov/vuln/detail/CVE-2021-42392","https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console/","https://security.netapp.com/advisory/ntap-20220119-0001/","https://lists.debian.org/debian-lts-announce/2022/02/msg00017.html","https://www.debian.org/security/2022/dsa-5076","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.secpod.com/blog/log4shell-critical-remote-code-execution-vulnerability-in-h2database-console/"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h376-j262-vhq6","description":"RCE in H2 Console"},"relatedVulnerabilities":[{"id":"CVE-2021-42392","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-42392","cwe":"CWE-502","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2021-42392","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-42392","date":"2026-10-08","epss":0.83176,"percentile":0.99672}],"urls":["https://github.com/h2database/h2database/security/advisories/GHSA-h376-j262-vhq6","https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console/","https://lists.debian.org/debian-lts-announce/2022/02/msg00017.html","https://security.netapp.com/advisory/ntap-20220119-0001/","https://www.debian.org/security/2022/dsa-5076","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.secpod.com/blog/log4shell-critical-remote-code-execution-vulnerability-in-h2database-console/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-42392","description":"The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution."}]},{"artifact":{"id":"3f92c454a30427fb","cpes":["cpe:2.3:a:org.springframework:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-webmvc","purl":"pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-webmvc-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-webmvc","archiveDigests":[{"value":"652abc943904d67504dc822197868cafaa5e56b5","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-webmvc-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.3.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wx2-9q48-vm9r","versionConstraint":">=5.2.0.RELEASE,<5.2.3.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-webmvc","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8wx2-9q48-vm9r","fix":{"state":"fixed","versions":["5.2.3.RELEASE"],"available":[{"date":"2022-12-16","kind":"first-observed","version":"5.2.3.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-5398","cwe":"CWE-79","type":"Secondary","source":"security@pivotal.io"},{"cve":"CVE-2020-5398","cwe":"CWE-494","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-5398","date":"2026-10-08","epss":0.88768,"percentile":0.99775}],"risk":66.57600000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-5398","https://pivotal.io/security/cve-2020-5398","https://lists.apache.org/thread.html/rf8dc72b974ee74f17bce661ea7d124e733a1f4c4f236354ac0cf48e8@%3Ccommits.camel.apache.org%3E","https://lists.apache.org/thread.html/rc05acaacad089613e9642f939b3a44f7199b5537493945c3e045287f@%3Cdev.geode.apache.org%3E","https://lists.apache.org/thread.html/rdcaadaa9a68b31b7d093d76eacfaacf6c7a819f976b595c75ad2d4dc@%3Cdev.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuapr2020.html","https://lists.apache.org/thread.html/r0f3530f7cb510036e497532ffc4e0bd0b882940448cf4e233994b08b@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r3765353ff434fd00d8fa5a44734b3625a06eeb2a3fb468da7dfae134@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r7361bfe84bde9d233f9800c3a96673e7bd81207549ced0236f07a29d@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r7d5e518088e2e778928b02bcd3be3b948b59acefe2f0ebb57ec2ebb0@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r8736185eb921022225a83e56d7285a217fd83f5524bd64a6ca3bf5cc@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r9fb1ee08cf337d16c3364feb0f35a072438c1a956afd7b77859aa090@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r028977b9b9d44a89823639aa3296fb0f0cfdd76b4450df89d3c4fbbf@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r1bc5d673c01cfbb8e4a91914e9748ead3e5f56b61bca54d314c0419b@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r4b1886e82cc98ef38f582fef7d4ea722e3fcf46637cd4674926ba682@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r74f81f93a9b69140fe41e236afa7cbe8dfa75692e7ab31a468fddaa0@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/rab0de39839b4c208dcd73f01e12899dc453361935a816a784548e048@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/reaa8a6674baf2724b1b88a621b0d72d9f7a6f5577c88759842c16eb6@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r0f2d0ae1bad2edb3d4a863d77f3097b5e88cfbdae7b809f4f42d6aad@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r1accbd4f31ad2f40e1661d70a4510a584eb3efd1e32e8660ccf46676@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r2dfd5b331b46d3f90c4dd63a060e9f04300468293874bd7e41af7163@%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r4639e821ef9ca6ca10887988f410a60261400a7766560e7a97a22efc@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r6dac0e365d1b2df9a7ffca12b4195181ec14ff0abdf59e1fdb088ce5@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r8cc37a60a5056351377ee5f1258f2a4fdd39822a257838ba6bcc1e88@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/rb4d1fc078f086ec2e98b2693e8b358e58a6a4ef903ceed93a1ee2b18@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r712a6fce928e24e7b6ec30994a7e115a70f1f6e4cf2c2fbf0347ce46@%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r881fb5a95ab251106fed38f836257276feb026bfe01290e72ff91c2a@%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/ra996b56e1f5ab2fed235a8b91fa0cc3cf34c2e9fee290b7fa4380a0d@%3Ccommits.servicecomb.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163@%3Ccommits.ambari.apache.org%3E","https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a@%3Cissues.ambari.apache.org%3E","https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5@%3Cissues.ambari.apache.org%3E","https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a@%3Cdev.ambari.apache.org%3E","https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1@%3Cdev.ambari.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.apache.org/thread.html/r27552d2fa10d96f2810c50d16ad1fd1899e37796c81a0c5e7585a02d@%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/r645408661a8df9158f49e337072df39838fa76da629a7e25a20928a6@%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/rc9c7f96f08c8554225dba9050ea5e64bebc129d0d836303143fe3160@%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/rded5291e25a4c4085a6d43cf262e479140198bf4eabb84986e0a1ef3@%3Cdev.rocketmq.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/spring-projects/spring-framework/commit/41f40c6c229d3b4f768718f1ec229d8f0ad76d76","https://security.netapp.com/advisory/ntap-20210917-0006"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wx2-9q48-vm9r","description":"RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application"},"relatedVulnerabilities":[{"id":"CVE-2020-5398","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.6,"impactScore":10.1,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@pivotal.io","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":6.1,"exploitabilityScore":1.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-5398","cwe":"CWE-79","type":"Secondary","source":"security@pivotal.io"},{"cve":"CVE-2020-5398","cwe":"CWE-494","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-5398","date":"2026-10-08","epss":0.88768,"percentile":0.99775}],"urls":["https://lists.apache.org/thread.html/r028977b9b9d44a89823639aa3296fb0f0cfdd76b4450df89d3c4fbbf%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r0f2d0ae1bad2edb3d4a863d77f3097b5e88cfbdae7b809f4f42d6aad%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r0f3530f7cb510036e497532ffc4e0bd0b882940448cf4e233994b08b%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r1accbd4f31ad2f40e1661d70a4510a584eb3efd1e32e8660ccf46676%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r1bc5d673c01cfbb8e4a91914e9748ead3e5f56b61bca54d314c0419b%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163%40%3Ccommits.ambari.apache.org%3E","https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a%40%3Cissues.ambari.apache.org%3E","https://lists.apache.org/thread.html/r27552d2fa10d96f2810c50d16ad1fd1899e37796c81a0c5e7585a02d%40%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/r2dfd5b331b46d3f90c4dd63a060e9f04300468293874bd7e41af7163%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r3765353ff434fd00d8fa5a44734b3625a06eeb2a3fb468da7dfae134%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r4639e821ef9ca6ca10887988f410a60261400a7766560e7a97a22efc%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r4b1886e82cc98ef38f582fef7d4ea722e3fcf46637cd4674926ba682%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5%40%3Cissues.ambari.apache.org%3E","https://lists.apache.org/thread.html/r645408661a8df9158f49e337072df39838fa76da629a7e25a20928a6%40%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/r6dac0e365d1b2df9a7ffca12b4195181ec14ff0abdf59e1fdb088ce5%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r712a6fce928e24e7b6ec30994a7e115a70f1f6e4cf2c2fbf0347ce46%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r7361bfe84bde9d233f9800c3a96673e7bd81207549ced0236f07a29d%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r74f81f93a9b69140fe41e236afa7cbe8dfa75692e7ab31a468fddaa0%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r7d5e518088e2e778928b02bcd3be3b948b59acefe2f0ebb57ec2ebb0%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r8736185eb921022225a83e56d7285a217fd83f5524bd64a6ca3bf5cc%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/r881fb5a95ab251106fed38f836257276feb026bfe01290e72ff91c2a%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a%40%3Cdev.ambari.apache.org%3E","https://lists.apache.org/thread.html/r8cc37a60a5056351377ee5f1258f2a4fdd39822a257838ba6bcc1e88%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1%40%3Cdev.ambari.apache.org%3E","https://lists.apache.org/thread.html/r9fb1ee08cf337d16c3364feb0f35a072438c1a956afd7b77859aa090%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/ra996b56e1f5ab2fed235a8b91fa0cc3cf34c2e9fee290b7fa4380a0d%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/rab0de39839b4c208dcd73f01e12899dc453361935a816a784548e048%40%3Cissues.karaf.apache.org%3E","https://lists.apache.org/thread.html/rb4d1fc078f086ec2e98b2693e8b358e58a6a4ef903ceed93a1ee2b18%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/rc05acaacad089613e9642f939b3a44f7199b5537493945c3e045287f%40%3Cdev.geode.apache.org%3E","https://lists.apache.org/thread.html/rc9c7f96f08c8554225dba9050ea5e64bebc129d0d836303143fe3160%40%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/rdcaadaa9a68b31b7d093d76eacfaacf6c7a819f976b595c75ad2d4dc%40%3Cdev.geode.apache.org%3E","https://lists.apache.org/thread.html/rded5291e25a4c4085a6d43cf262e479140198bf4eabb84986e0a1ef3%40%3Cdev.rocketmq.apache.org%3E","https://lists.apache.org/thread.html/reaa8a6674baf2724b1b88a621b0d72d9f7a6f5577c88759842c16eb6%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/rf8dc72b974ee74f17bce661ea7d124e733a1f4c4f236354ac0cf48e8%40%3Ccommits.camel.apache.org%3E","https://pivotal.io/security/cve-2020-5398","https://security.netapp.com/advisory/ntap-20210917-0006/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-5398","description":"In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a \"Content-Disposition\" header in the response where the filename attribute is derived from user supplied input."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3711","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3711","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.13"],"available":[{"date":"2021-08-24","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3711","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3711","date":"2026-10-08","epss":0.87816,"percentile":0.9976}],"risk":65.862,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3711"},"relatedVulnerabilities":[{"id":"CVE-2021-3711","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3711","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3711","date":"2026-10-08","epss":0.87816,"percentile":0.9976}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/26/2","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=59f5e75f3bced8fc0e130d72a3f582cf7b480b46","https://lists.apache.org/thread.html/r18995de860f0e63635f3008fd2a6aca82394249476d21691e7c59c9e%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad5d9f83f0d11fb3f8bb148d179b8a9ad7c6a17f18d70e5805a713d1%40%3Cdev.tomcat.apache.org%3E","https://security.gentoo.org/glsa/202209-02","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20210827-0010/","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4963","https://www.openssl.org/news/secadv/20210824.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-16","https://www.tenable.com/security/tns-2022-02"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3711","description":"In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the \"out\" parameter can be NULL and, on exit, the \"outlen\" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the \"out\" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3711","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3711","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.13"],"available":[{"date":"2021-08-24","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3711","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3711","date":"2026-10-08","epss":0.87816,"percentile":0.9976}],"risk":65.862,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3711"},"relatedVulnerabilities":[{"id":"CVE-2021-3711","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3711","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3711","date":"2026-10-08","epss":0.87816,"percentile":0.9976}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/26/2","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=59f5e75f3bced8fc0e130d72a3f582cf7b480b46","https://lists.apache.org/thread.html/r18995de860f0e63635f3008fd2a6aca82394249476d21691e7c59c9e%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad5d9f83f0d11fb3f8bb148d179b8a9ad7c6a17f18d70e5805a713d1%40%3Cdev.tomcat.apache.org%3E","https://security.gentoo.org/glsa/202209-02","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20210827-0010/","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4963","https://www.openssl.org/news/secadv/20210824.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-16","https://www.tenable.com/security/tns-2022-02"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3711","description":"In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the \"out\" parameter can be NULL and, on exit, the \"outlen\" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the \"out\" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k)."}]},{"artifact":{"id":"a819527c2e72cbc0","cpes":["cpe:2.3:a:apache:tomcat-embed-websocket:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_websocket:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-websocket","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-websocket-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-websocket","archiveDigests":[{"value":"8d2b93a8621a83d9283a46cae09d8f87bea877fa","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-websocket-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.37"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m7jv-hq7h-mq7c","versionConstraint":">=9.0.0.M1,<9.0.37 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-websocket","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-m7jv-hq7h-mq7c","fix":{"state":"fixed","versions":["9.0.37"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"9.0.37"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-13935","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13935","date":"2026-10-08","epss":0.86608,"percentile":0.99737}],"risk":64.95599999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-13935","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html","https://www.debian.org/security/2020/dsa-4727","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://github.com/apache/tomcat/commit/12d715676038efbf9c728af10163f8277fc019d5","https://github.com/apache/tomcat/commit/1c1c77b0efb667cea80b532440b44cea1dc427c3","https://github.com/apache/tomcat/commit/40fa74c74822711ab878079d0a69f7357926723d","https://github.com/apache/tomcat/commit/4c04982870d6e730c38e21e58fb653b7cf723784","https://github.com/apache/tomcat/commit/f9f75c14678b68633f79030ddf4ff827f014cc84","https://usn.ubuntu.com/4596-1","https://usn.ubuntu.com/4448-1","https://security.netapp.com/advisory/ntap-20200724-0003","https://tomcat.apache.org/security-9.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-7.html","https://tomcat.apache.org/security-10.html","https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50%40%3Cusers.tomcat.apache.org%3E"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m7jv-hq7h-mq7c","description":"Infinite Loop in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2020-13935","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-13935","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13935","date":"2026-10-08","epss":0.86608,"percentile":0.99737}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html","https://security.netapp.com/advisory/ntap-20200724-0003/","https://usn.ubuntu.com/4448-1/","https://usn.ubuntu.com/4596-1/","https://www.debian.org/security/2020/dsa-4727","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-13935","description":"The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service."}]},{"artifact":{"id":"958287065b0f2a45","cpes":["cpe:2.3:a:org.h2.util.DbDriverActivator:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:DbDriverActivator:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:org.h2.util.DbDriverActivator:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:com.h2database:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:org.h2.util.DbDriverActivator:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2database:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:DbDriverActivator:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:util:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:DbDriverActivator:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:com.h2database:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:com.h2database:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2database:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2database:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:util:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:util:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2:h2:1.4.200:*:*:*:*:*:*:*"],"name":"h2","purl":"pkg:maven/com.h2database/h2@1.4.200","type":"java-archive","version":"1.4.200","language":"java","licenses":["https://h2database.com/html/license.html"],"metadata":{"pomGroupID":"com.h2database","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/h2-1.4.200.jar","manifestName":"","pomArtifactID":"h2","archiveDigests":[{"value":"f7533fe7cb8e99c87a43d325a77b4b678ad9031a","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/h2-1.4.200.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.1.210"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-45hx-wfhj-473x","versionConstraint":"<2.1.210 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.h2database:h2","version":"1.4.200"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-45hx-wfhj-473x","fix":{"state":"fixed","versions":["2.1.210"],"available":[{"date":"2022-01-22","kind":"first-observed","version":"2.1.210"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23221","cwe":"CWE-88","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23221","cwe":"CWE-88","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23221","date":"2026-10-08","epss":0.64766,"percentile":0.99229}],"risk":60.88004,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-23221","https://github.com/h2database/h2database/releases/tag/version-2.1.210","https://github.com/h2database/h2database/security/advisories","https://twitter.com/d0nkey_man/status/1483824727936450564","http://packetstormsecurity.com/files/165676/H2-Database-Console-Remote-Code-Execution.html","http://seclists.org/fulldisclosure/2022/Jan/39","https://lists.debian.org/debian-lts-announce/2022/02/msg00017.html","https://www.debian.org/security/2022/dsa-5076","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://security.netapp.com/advisory/ntap-20230818-0011/"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-45hx-wfhj-473x","description":"Arbitrary code execution in H2 Console"},"relatedVulnerabilities":[{"id":"CVE-2022-23221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23221","cwe":"CWE-88","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23221","cwe":"CWE-88","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23221","date":"2026-10-08","epss":0.64766,"percentile":0.99229}],"urls":["http://packetstormsecurity.com/files/165676/H2-Database-Console-Remote-Code-Execution.html","http://seclists.org/fulldisclosure/2022/Jan/39","https://github.com/h2database/h2database/releases/tag/version-2.1.210","https://github.com/h2database/h2database/security/advisories","https://lists.debian.org/debian-lts-announce/2022/02/msg00017.html","https://security.netapp.com/advisory/ntap-20230818-0011/","https://twitter.com/d0nkey_man/status/1483824727936450564","https://www.debian.org/security/2022/dsa-5076","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23221","description":"H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.81"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qppj-fm5r-hxr3","versionConstraint":">=9.0.0,<9.0.81 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qppj-fm5r-hxr3","fix":{"state":"fixed","versions":["9.0.81"],"available":[{"date":"2023-12-22","kind":"first-observed","version":"9.0.81"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:H","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:A","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-44487","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-44487","date":"2026-10-08","epss":0.99999,"percentile":0.99998}],"risk":58.275,"urls":["https://github.com/apple/swift-nio-http2/security/advisories/GHSA-qppj-fm5r-hxr3","https://nvd.nist.gov/vuln/detail/CVE-2023-44487","https://github.com/alibaba/tengine/issues/1872","https://github.com/caddyserver/caddy/issues/5877","https://github.com/eclipse/jetty.project/issues/10679","https://github.com/haproxy/haproxy/issues/2312","https://github.com/hyperium/hyper/issues/3337","https://github.com/envoyproxy/envoy/pull/30055","https://github.com/grpc/grpc-go/pull/6703","https://github.com/nghttp2/nghttp2/pull/1961","https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61","https://bugzilla.proxmox.com/show_bug.cgi?id=4988","https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9","https://chaos.social/@icing/111210915918780532","https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack","https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764","https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2","https://github.com/bcdannyboy/CVE-2023-44487","https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244","https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0","https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html","https://my.f5.com/manage/s/article/K000137106","https://news.ycombinator.com/item?id=37830987","https://news.ycombinator.com/item?id=37830998","https://news.ycombinator.com/item?id=37831062","https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack","https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf","https://github.com/dotnet/announcements/issues/277","https://github.com/golang/go/issues/63417","https://github.com/apache/trafficserver/pull/10564","https://github.com/facebook/proxygen/pull/466","https://github.com/h2o/h2o/pull/3291","https://github.com/microsoft/CBL-Mariner/pull/6381","https://github.com/nodejs/node/pull/50121","https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve","https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088","https://github.com/advisories/GHSA-vx74-f528-fxqg","https://github.com/micrictor/http2-rst-stream","https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo","https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487","https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected","https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14","https://www.openwall.com/lists/oss-security/2023/10/10/6","https://github.com/opensearch-project/data-prepper/issues/3474","https://github.com/kubernetes/kubernetes/pull/121120","https://github.com/advisories/GHSA-xpw8-rcwv-8f8p","https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73","https://github.com/oqtane/oqtane.framework/discussions/3367","https://netty.io/news/2023/10/10/4-1-100-Final.html","https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487","https://github.com/Azure/AKS/issues/3947","https://github.com/akka/akka-http/issues/4323","https://github.com/apache/apisix/issues/10320","https://github.com/etcd-io/etcd/issues/16740","https://github.com/junkurihara/rust-rpxy/issues/97","https://github.com/kazu-yamamoto/http2/issues/93","https://github.com/ninenines/cowboy/issues/1615","https://github.com/openresty/openresty/issues/930","https://github.com/tempesta-tech/tempesta/issues/1986","https://github.com/varnishcache/varnish-cache/issues/3996","https://github.com/apache/httpd-site/pull/10","https://github.com/line/armeria/pull/5232","https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632","https://github.com/projectcontour/contour/pull/5826","https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1","https://access.redhat.com/security/cve/cve-2023-44487","https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack","https://bugzilla.redhat.com/show_bug.cgi?id=2242803","https://bugzilla.suse.com/show_bug.cgi?id=1216123","https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125","https://github.com/Kong/kong/discussions/11741","https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113","https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487","https://github.com/caddyserver/caddy/releases/tag/v2.7.5","https://go.dev/cl/534215","https://go.dev/cl/534235","https://go.dev/issue/63417","https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo/m/UDd7VKQuAAAJ","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html","https://news.ycombinator.com/item?id=37837043","https://security.paloaltonetworks.com/CVE-2023-44487","https://ubuntu.com/security/CVE-2023-44487","https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522","http://www.openwall.com/lists/oss-security/2023/10/13/4","http://www.openwall.com/lists/oss-security/2023/10/13/9","https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html","https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html","https://github.com/grpc/grpc-go/releases","https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html","https://www.debian.org/security/2023/dsa-5540","http://www.openwall.com/lists/oss-security/2023/10/18/4","http://www.openwall.com/lists/oss-security/2023/10/18/8","http://www.openwall.com/lists/oss-security/2023/10/19/6","http://www.openwall.com/lists/oss-security/2023/10/20/8","https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715","https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html","https://www.debian.org/security/2023/dsa-5549","https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html","https://security.gentoo.org/glsa/202311-09","https://www.debian.org/security/2023/dsa-5558","https://www.debian.org/security/2023/dsa-5570","https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M12","https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.94","https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.81","https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size","https://aws.amazon.com/security/security-bulletins/AWS-2023-011","https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack","https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack","https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty","https://blog.vespa.ai/cve-2023-44487","https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps","https://istio.io/latest/news/security/istio-security-2023-004","https://linkerd.io/2023/10/12/linkerd-cve-2023-44487","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4","https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2","https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response","https://security.netapp.com/advisory/ntap-20231016-0001","https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records","https://www.eclipse.org/lists/jetty-announce/msg00181.html","https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487","https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products","https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday","https://github.com/akka/akka-http/pull/4325","https://github.com/akka/akka-http/pull/4324","https://akka.io/security/akka-http-cve-2023-44487.html","https://security.netapp.com/advisory/ntap-20240426-0007","https://security.netapp.com/advisory/ntap-20240621-0006","https://security.netapp.com/advisory/ntap-20240621-0007","https://github.com/apache/tomcat/commit/944332bb15bd2f3bf76ec2caeb1ff0a58a3bc628","https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX","https://github.com/grpc/grpc/releases/tag/v1.59.2","http://www.openwall.com/lists/oss-security/2023/10/10/6","http://www.openwall.com/lists/oss-security/2023/10/10/7","https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-341067.html","https://cert-portal.siemens.com/productcert/html/ssa-784301.html","https://cert-portal.siemens.com/productcert/html/ssa-832273.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html","http://www.openwall.com/lists/oss-security/2025/08/13/6"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qppj-fm5r-hxr3","description":"HTTP/2 Stream Cancellation Attack","knownExploited":[{"cve":"CVE-2023-44487","cwes":["CWE-400"],"urls":["https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://nvd.nist.gov/vuln/detail/CVE-2023-44487"],"notes":"This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","dueDate":"2023-10-31","product":"HTTP/2","dateAdded":"2023-10-10","vendorProject":"IETF","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2023-44487","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-44487","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-44487","date":"2026-10-08","epss":0.99999,"percentile":0.99998}],"urls":["http://www.openwall.com/lists/oss-security/2023/10/10/6","http://www.openwall.com/lists/oss-security/2023/10/10/7","http://www.openwall.com/lists/oss-security/2023/10/13/4","http://www.openwall.com/lists/oss-security/2023/10/13/9","http://www.openwall.com/lists/oss-security/2023/10/18/4","http://www.openwall.com/lists/oss-security/2023/10/18/8","http://www.openwall.com/lists/oss-security/2023/10/19/6","http://www.openwall.com/lists/oss-security/2023/10/20/8","https://access.redhat.com/security/cve/cve-2023-44487","https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/","https://aws.amazon.com/security/security-bulletins/AWS-2023-011/","https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/","https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/","https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack","https://blog.vespa.ai/cve-2023-44487/","https://bugzilla.proxmox.com/show_bug.cgi?id=4988","https://bugzilla.redhat.com/show_bug.cgi?id=2242803","https://bugzilla.suse.com/show_bug.cgi?id=1216123","https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9","https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/","https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack","https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125","https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715","https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve","https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764","https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088","https://github.com/Azure/AKS/issues/3947","https://github.com/Kong/kong/discussions/11741","https://github.com/advisories/GHSA-qppj-fm5r-hxr3","https://github.com/advisories/GHSA-vx74-f528-fxqg","https://github.com/advisories/GHSA-xpw8-rcwv-8f8p","https://github.com/akka/akka-http/issues/4323","https://github.com/alibaba/tengine/issues/1872","https://github.com/apache/apisix/issues/10320","https://github.com/apache/httpd-site/pull/10","https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113","https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2","https://github.com/apache/trafficserver/pull/10564","https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487","https://github.com/bcdannyboy/CVE-2023-44487","https://github.com/caddyserver/caddy/issues/5877","https://github.com/caddyserver/caddy/releases/tag/v2.7.5","https://github.com/dotnet/announcements/issues/277","https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73","https://github.com/eclipse/jetty.project/issues/10679","https://github.com/envoyproxy/envoy/pull/30055","https://github.com/etcd-io/etcd/issues/16740","https://github.com/facebook/proxygen/pull/466","https://github.com/golang/go/issues/63417","https://github.com/grpc/grpc-go/pull/6703","https://github.com/grpc/grpc/releases/tag/v1.59.2","https://github.com/h2o/h2o/pull/3291","https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf","https://github.com/haproxy/haproxy/issues/2312","https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244","https://github.com/junkurihara/rust-rpxy/issues/97","https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1","https://github.com/kazu-yamamoto/http2/issues/93","https://github.com/kubernetes/kubernetes/pull/121120","https://github.com/line/armeria/pull/5232","https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632","https://github.com/micrictor/http2-rst-stream","https://github.com/microsoft/CBL-Mariner/pull/6381","https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61","https://github.com/nghttp2/nghttp2/pull/1961","https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0","https://github.com/ninenines/cowboy/issues/1615","https://github.com/nodejs/node/pull/50121","https://github.com/openresty/openresty/issues/930","https://github.com/opensearch-project/data-prepper/issues/3474","https://github.com/oqtane/oqtane.framework/discussions/3367","https://github.com/projectcontour/contour/pull/5826","https://github.com/tempesta-tech/tempesta/issues/1986","https://github.com/varnishcache/varnish-cache/issues/3996","https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo","https://istio.io/latest/news/security/istio-security-2023-004/","https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/","https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html","https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html","https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/","https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html","https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html","https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html","https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487","https://my.f5.com/manage/s/article/K000137106","https://netty.io/news/2023/10/10/4-1-100-Final.html","https://news.ycombinator.com/item?id=37830987","https://news.ycombinator.com/item?id=37830998","https://news.ycombinator.com/item?id=37831062","https://news.ycombinator.com/item?id=37837043","https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/","https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected","https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20231016-0001/","https://security.netapp.com/advisory/ntap-20240426-0007/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://security.netapp.com/advisory/ntap-20240621-0007/","https://security.paloaltonetworks.com/CVE-2023-44487","https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14","https://ubuntu.com/security/CVE-2023-44487","https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/","https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522","https://www.debian.org/security/2023/dsa-5540","https://www.debian.org/security/2023/dsa-5549","https://www.debian.org/security/2023/dsa-5558","https://www.debian.org/security/2023/dsa-5570","https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487","https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/","https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/","https://www.openwall.com/lists/oss-security/2023/10/10/6","https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack","https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/","http://www.openwall.com/lists/oss-security/2025/08/13/6","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/","https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-341067.html","https://cert-portal.siemens.com/productcert/html/ssa-784301.html","https://cert-portal.siemens.com/productcert/html/ssa-832273.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487","https://github.com/envoyproxy/envoy/security/advisories/GHSA-jhv4-f7mr-xx76","https://github.com/kubernetes/ingress-nginx/blob/4b5c5efe2508dc915a48c54de7f23912ff2ec695/changelog/controller-1.9.3.md?plain=1#L15","https://varnish-cache.org/releases/rel6.0.12.html#rel6-0-12","https://varnish-cache.org/releases/rel7.3.1.html#rel7-3-1","https://varnish-cache.org/releases/rel7.4.2.html#rel7-4-2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-44487","description":"The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.","knownExploited":[{"cve":"CVE-2023-44487","cwes":["CWE-400"],"urls":["https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/","https://nvd.nist.gov/vuln/detail/CVE-2023-44487"],"notes":"This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487","dueDate":"2023-10-31","product":"HTTP/2","dateAdded":"2023-10-10","vendorProject":"IETF","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0778","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0778","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.15"],"available":[{"date":"2022-03-15","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-0778","date":"2026-10-08","epss":0.73188,"percentile":0.99448}],"risk":54.891,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0778"},"relatedVulnerabilities":[{"id":"CVE-2022-0778","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-0778","date":"2026-10-08","epss":0.73188,"percentile":0.99448}],"urls":["http://packetstormsecurity.com/files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html","http://seclists.org/fulldisclosure/2022/May/33","http://seclists.org/fulldisclosure/2022/May/35","http://seclists.org/fulldisclosure/2022/May/38","https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246","https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html","https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0002","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220321-0002/","https://security.netapp.com/advisory/ntap-20220429-0005/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://support.apple.com/kb/HT213255","https://support.apple.com/kb/HT213256","https://support.apple.com/kb/HT213257","https://www.debian.org/security/2022/dsa-5103","https://www.openssl.org/news/secadv/20220315.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.tenable.com/security/tns-2022-06","https://www.tenable.com/security/tns-2022-07","https://www.tenable.com/security/tns-2022-08","https://www.tenable.com/security/tns-2022-09","https://cert-portal.siemens.com/productcert/html/ssa-019200.html","https://cert-portal.siemens.com/productcert/html/ssa-028723.html","https://cert-portal.siemens.com/productcert/html/ssa-108696.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-712929.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0778","description":"The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-0778","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0778","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.15"],"available":[{"date":"2022-03-15","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-0778","date":"2026-10-08","epss":0.73188,"percentile":0.99448}],"risk":54.891,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0778"},"relatedVulnerabilities":[{"id":"CVE-2022-0778","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-0778","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-0778","date":"2026-10-08","epss":0.73188,"percentile":0.99448}],"urls":["http://packetstormsecurity.com/files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html","http://seclists.org/fulldisclosure/2022/May/33","http://seclists.org/fulldisclosure/2022/May/35","http://seclists.org/fulldisclosure/2022/May/38","https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246","https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html","https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0002","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220321-0002/","https://security.netapp.com/advisory/ntap-20220429-0005/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://support.apple.com/kb/HT213255","https://support.apple.com/kb/HT213256","https://support.apple.com/kb/HT213257","https://www.debian.org/security/2022/dsa-5103","https://www.openssl.org/news/secadv/20220315.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.tenable.com/security/tns-2022-06","https://www.tenable.com/security/tns-2022-07","https://www.tenable.com/security/tns-2022-08","https://www.tenable.com/security/tns-2022-09","https://cert-portal.siemens.com/productcert/html/ssa-019200.html","https://cert-portal.siemens.com/productcert/html/ssa-028723.html","https://cert-portal.siemens.com/productcert/html/ssa-108696.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-712929.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0778","description":"The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc)."}]},{"artifact":{"id":"1aef213d2b0dcd29","cpes":["cpe:2.3:a:libfreetype6:libfreetype6:2.8.1-2ubuntu2:*:*:*:*:*:*:*"],"name":"libfreetype6","purl":"pkg:deb/ubuntu/libfreetype6@2.8.1-2ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=freetype","type":"deb","version":"2.8.1-2ubuntu2","language":"","licenses":["BSD-2-Clause","BSD-3-Clause","Catharon-OSL","FTL","GPL-2","GPL-2+","GZip","OpenGroup-BSD-like"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfreetype6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libfreetype6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"freetype"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-27363","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"freetype","version":"2.8.1-2ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2025-27363","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-27363","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-27363","date":"2026-10-08","epss":0.27775,"percentile":0.98048}],"risk":52.5,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-27363","knownExploited":[{"cve":"CVE-2025-27363","cwes":["CWE-787"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-27363"],"notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://source.android.com/docs/security/bulletin/2025-05-01","dueDate":"2025-05-27","product":"FreeType","dateAdded":"2025-05-06","vendorProject":"FreeType","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]},"relatedVulnerabilities":[{"id":"CVE-2025-27363","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-assign@fb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-27363","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-27363","date":"2026-10-08","epss":0.27775,"percentile":0.98048}],"urls":["https://www.facebook.com/security/advisories/cve-2025-27363","http://www.openwall.com/lists/oss-security/2025/03/13/1","http://www.openwall.com/lists/oss-security/2025/03/13/11","http://www.openwall.com/lists/oss-security/2025/03/13/12","http://www.openwall.com/lists/oss-security/2025/03/13/2","http://www.openwall.com/lists/oss-security/2025/03/13/3","http://www.openwall.com/lists/oss-security/2025/03/13/8","http://www.openwall.com/lists/oss-security/2025/03/14/1","http://www.openwall.com/lists/oss-security/2025/03/14/2","http://www.openwall.com/lists/oss-security/2025/03/14/3","http://www.openwall.com/lists/oss-security/2025/03/14/4","http://www.openwall.com/lists/oss-security/2025/05/06/3","http://www.openwall.com/lists/oss-security/2026/04/16/5","http://www.openwall.com/lists/oss-security/2026/04/19/3","https://lists.debian.org/debian-lts-announce/2025/03/msg00030.html","https://source.android.com/docs/security/bulletin/2025-05-01","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27363"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-27363","description":"An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.","knownExploited":[{"cve":"CVE-2025-27363","cwes":["CWE-787"],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-27363"],"notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://source.android.com/docs/security/bulletin/2025-05-01","dueDate":"2025-05-27","product":"FreeType","dateAdded":"2025-05-06","vendorProject":"FreeType","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","knownRansomwareCampaignUse":"unknown"}]}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.109"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wmwf-9ccg-fff5","versionConstraint":">=9.0.0-M11,<9.0.109 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wmwf-9ccg-fff5","fix":{"state":"fixed","versions":["9.0.109"],"available":[{"date":"2025-10-29","kind":"first-observed","version":"9.0.109"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55752","cwe":"CWE-23","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-55752","date":"2026-10-08","epss":0.64413,"percentile":0.99219}],"risk":48.631815,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-55752","https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog","https://github.com/apache/tomcat/commit/130d36d8492ef9e4eb22952c17c92423cb35fd06","https://github.com/apache/tomcat/commit/b5042622b8b78340ae65403c55dcb9c7416924df","https://github.com/apache/tomcat/commit/fec06c610ed7466b401e29cc567a58aee5ed826a","https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.45","https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.11","https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.109","http://www.openwall.com/lists/oss-security/2025/10/27/4","https://www.vicarius.io/vsociety/posts/cve-2025-55752-detect-apache-tomcat-vulnerability","https://www.vicarius.io/vsociety/posts/cve-2025-55752-mitigate-apache-tomcat-vulnerability","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wmwf-9ccg-fff5","description":"Apache Tomcat Vulnerable to Relative Path Traversal"},"relatedVulnerabilities":[{"id":"CVE-2025-55752","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55752","cwe":"CWE-23","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-55752","date":"2026-10-08","epss":0.64413,"percentile":0.99219}],"urls":["https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog","http://www.openwall.com/lists/oss-security/2025/10/27/4","https://www.vicarius.io/vsociety/posts/cve-2025-55752-detect-apache-tomcat-vulnerability","https://www.vicarius.io/vsociety/posts/cve-2025-55752-mitigate-apache-tomcat-vulnerability","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55752","description":"Relative Path Traversal vulnerability in Apache Tomcat.\n\nThe fix for bug 60013 introduced a regression where the       rewritten URL was normalized before it was decoded. This introduced the       possibility that, for rewrite rules that rewrite query parameters to the       URL, an attacker could manipulate the request URI to bypass security       constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108.\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected.\nUsers are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-2068","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-2068","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.19"],"available":[{"date":"2022-06-21","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-2068","date":"2026-10-08","epss":0.95404,"percentile":0.99869}],"risk":47.702,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-2068"},"relatedVulnerabilities":[{"id":"CVE-2022-2068","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-2068","date":"2026-10-08","epss":0.95404,"percentile":0.99869}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2c9c35870601b4a44d86ddbf512b38df38285cfa","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7a9c027159fe9e1bbc2cd38a8a2914bff0d5abd9","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9639817dac8bbbaa64d09efad7464ccc405527c7","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WZZBKUHQFGSKGNXXKICSRPL7AMVW5M5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/","https://security.netapp.com/advisory/ntap-20220707-0008/","https://www.debian.org/security/2022/dsa-5169","https://www.openssl.org/news/secadv/20220621.txt","http://seclists.org/fulldisclosure/2024/Nov/0","https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-2068","description":"In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.19"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-2068","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-2068","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.19"],"available":[{"date":"2022-06-21","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-2068","date":"2026-10-08","epss":0.95404,"percentile":0.99869}],"risk":47.702,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-2068"},"relatedVulnerabilities":[{"id":"CVE-2022-2068","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-2068","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-2068","date":"2026-10-08","epss":0.95404,"percentile":0.99869}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2c9c35870601b4a44d86ddbf512b38df38285cfa","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7a9c027159fe9e1bbc2cd38a8a2914bff0d5abd9","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9639817dac8bbbaa64d09efad7464ccc405527c7","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WZZBKUHQFGSKGNXXKICSRPL7AMVW5M5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/","https://security.netapp.com/advisory/ntap-20220707-0008/","https://www.debian.org/security/2022/dsa-5169","https://www.openssl.org/news/secadv/20220621.txt","http://seclists.org/fulldisclosure/2024/Nov/0","https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-2068","description":"In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze)."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3449","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3449","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.9"],"available":[{"date":"2021-03-25","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3449","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3449","date":"2026-10-08","epss":0.63542,"percentile":0.99195}],"risk":47.6565,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3449"},"relatedVulnerabilities":[{"id":"CVE-2021-3449","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3449","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3449","date":"2026-10-08","epss":0.63542,"percentile":0.99195}],"urls":["http://www.openwall.com/lists/oss-security/2021/03/27/1","http://www.openwall.com/lists/oss-security/2021/03/27/2","http://www.openwall.com/lists/oss-security/2021/03/28/3","http://www.openwall.com/lists/oss-security/2021/03/28/4","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-772220.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fb9fa6b51defd48157eeb207f52181f735d96148","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845","https://kc.mcafee.com/corporate/index?page=content&id=SB10356","https://lists.debian.org/debian-lts-announce/2021/08/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013","https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.asc","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210326-0006/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd","https://www.debian.org/security/2021/dsa-4875","https://www.openssl.org/news/secadv/20210325.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-05","https://www.tenable.com/security/tns-2021-06","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3449","description":"An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3449","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3449","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.9"],"available":[{"date":"2021-03-25","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3449","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3449","date":"2026-10-08","epss":0.63542,"percentile":0.99195}],"risk":47.6565,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3449"},"relatedVulnerabilities":[{"id":"CVE-2021-3449","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3449","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3449","date":"2026-10-08","epss":0.63542,"percentile":0.99195}],"urls":["http://www.openwall.com/lists/oss-security/2021/03/27/1","http://www.openwall.com/lists/oss-security/2021/03/27/2","http://www.openwall.com/lists/oss-security/2021/03/28/3","http://www.openwall.com/lists/oss-security/2021/03/28/4","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-772220.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fb9fa6b51defd48157eeb207f52181f735d96148","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845","https://kc.mcafee.com/corporate/index?page=content&id=SB10356","https://lists.debian.org/debian-lts-announce/2021/08/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013","https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.asc","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210326-0006/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd","https://www.debian.org/security/2021/dsa-4875","https://www.openssl.org/news/secadv/20210325.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-05","https://www.tenable.com/security/tns-2021-06","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3449","description":"An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j)."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-0286","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-0286","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0286","date":"2026-10-08","epss":0.59501,"percentile":0.99104}],"risk":44.625750000000004,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-0286"},"relatedVulnerabilities":[{"id":"CVE-2023-0286","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0286","date":"2026-10-08","epss":0.59501,"percentile":0.99104}],"urls":["https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.6.2-relnotes.txt","https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/018_x509.patch.sig","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2c6c9d439b484e1ba9830d8454a34fa4f80fdfe9","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2f7530077e0ef79d98718138716bc51ca0cad658","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fd2af07dc083a350c959147097003a14a5e8ac4d","https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0286","description":"There is a type confusion vulnerability relating to X.400 address processing\ninside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but\nthe public structure definition for GENERAL_NAME incorrectly specified the type\nof the x400Address field as ASN1_TYPE. This field is subsequently interpreted by\nthe OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an\nASN1_STRING.\n\nWhen CRL checking is enabled (i.e. the application sets the\nX509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass\narbitrary pointers to a memcmp call, enabling them to read memory contents or\nenact a denial of service. In most cases, the attack requires the attacker to\nprovide both the certificate chain and CRL, neither of which need to have a\nvalid signature. If the attacker only controls one of these inputs, the other\ninput must already contain an X.400 address as a CRL distribution point, which\nis uncommon. As such, this vulnerability is most likely to only affect\napplications which have implemented their own functionality for retrieving CRLs\nover a network."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-0286","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-0286","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0286","date":"2026-10-08","epss":0.59501,"percentile":0.99104}],"risk":44.625750000000004,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-0286"},"relatedVulnerabilities":[{"id":"CVE-2023-0286","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0286","cwe":"CWE-843","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0286","date":"2026-10-08","epss":0.59501,"percentile":0.99104}],"urls":["https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.6.2-relnotes.txt","https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/018_x509.patch.sig","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2c6c9d439b484e1ba9830d8454a34fa4f80fdfe9","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2f7530077e0ef79d98718138716bc51ca0cad658","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fd2af07dc083a350c959147097003a14a5e8ac4d","https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0286","description":"There is a type confusion vulnerability relating to X.400 address processing\ninside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but\nthe public structure definition for GENERAL_NAME incorrectly specified the type\nof the x400Address field as ASN1_TYPE. This field is subsequently interpreted by\nthe OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an\nASN1_STRING.\n\nWhen CRL checking is enabled (i.e. the application sets the\nX509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass\narbitrary pointers to a memcmp call, enabling them to read memory contents or\nenact a denial of service. In most cases, the attack requires the attacker to\nprovide both the certificate chain and CRL, neither of which need to have a\nvalid signature. If the attacker only controls one of these inputs, the other\ninput must already contain an X.400 address as a CRL distribution point, which\nis uncommon. As such, this vulnerability is most likely to only affect\napplications which have implemented their own functionality for retrieving CRLs\nover a network."}]},{"artifact":{"id":"685ff832fa5df143","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"risk":44.165,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2961"},"relatedVulnerabilities":[{"id":"CVE-2024-2961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"impactScore":4.8,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/17/9","http://www.openwall.com/lists/oss-security/2024/04/18/4","http://www.openwall.com/lists/oss-security/2024/04/24/2","http://www.openwall.com/lists/oss-security/2024/05/27/1","http://www.openwall.com/lists/oss-security/2024/05/27/2","http://www.openwall.com/lists/oss-security/2024/05/27/3","http://www.openwall.com/lists/oss-security/2024/05/27/4","http://www.openwall.com/lists/oss-security/2024/05/27/5","http://www.openwall.com/lists/oss-security/2024/05/27/6","http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/","https://security.netapp.com/advisory/ntap-20240531-0002/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004","https://www.ambionics.io/blog/iconv-cve-2024-2961-p1","https://www.ambionics.io/blog/iconv-cve-2024-2961-p2","https://www.ambionics.io/blog/iconv-cve-2024-2961-p3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2961","description":"The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable."}]},{"artifact":{"id":"71315b6fa75a7166","cpes":["cpe:2.3:a:libc6:libc6:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"risk":44.165,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2961"},"relatedVulnerabilities":[{"id":"CVE-2024-2961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"impactScore":4.8,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/17/9","http://www.openwall.com/lists/oss-security/2024/04/18/4","http://www.openwall.com/lists/oss-security/2024/04/24/2","http://www.openwall.com/lists/oss-security/2024/05/27/1","http://www.openwall.com/lists/oss-security/2024/05/27/2","http://www.openwall.com/lists/oss-security/2024/05/27/3","http://www.openwall.com/lists/oss-security/2024/05/27/4","http://www.openwall.com/lists/oss-security/2024/05/27/5","http://www.openwall.com/lists/oss-security/2024/05/27/6","http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/","https://security.netapp.com/advisory/ntap-20240531-0002/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004","https://www.ambionics.io/blog/iconv-cve-2024-2961-p1","https://www.ambionics.io/blog/iconv-cve-2024-2961-p2","https://www.ambionics.io/blog/iconv-cve-2024-2961-p3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2961","description":"The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable."}]},{"artifact":{"id":"62a0389fd254614a","cpes":["cpe:2.3:a:locales:locales:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.27-3ubuntu1?arch=all&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"risk":44.165,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2961"},"relatedVulnerabilities":[{"id":"CVE-2024-2961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"impactScore":4.8,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/17/9","http://www.openwall.com/lists/oss-security/2024/04/18/4","http://www.openwall.com/lists/oss-security/2024/04/24/2","http://www.openwall.com/lists/oss-security/2024/05/27/1","http://www.openwall.com/lists/oss-security/2024/05/27/2","http://www.openwall.com/lists/oss-security/2024/05/27/3","http://www.openwall.com/lists/oss-security/2024/05/27/4","http://www.openwall.com/lists/oss-security/2024/05/27/5","http://www.openwall.com/lists/oss-security/2024/05/27/6","http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/","https://security.netapp.com/advisory/ntap-20240531-0002/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004","https://www.ambionics.io/blog/iconv-cve-2024-2961-p1","https://www.ambionics.io/blog/iconv-cve-2024-2961-p2","https://www.ambionics.io/blog/iconv-cve-2024-2961-p3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2961","description":"The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable."}]},{"artifact":{"id":"6c475aa8af85f1cd","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2961","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2961","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"risk":44.165,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2961"},"relatedVulnerabilities":[{"id":"CVE-2024-2961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"impactScore":4.8,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2961","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2024-2961","date":"2026-10-08","epss":0.8833,"percentile":0.99769}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/17/9","http://www.openwall.com/lists/oss-security/2024/04/18/4","http://www.openwall.com/lists/oss-security/2024/04/24/2","http://www.openwall.com/lists/oss-security/2024/05/27/1","http://www.openwall.com/lists/oss-security/2024/05/27/2","http://www.openwall.com/lists/oss-security/2024/05/27/3","http://www.openwall.com/lists/oss-security/2024/05/27/4","http://www.openwall.com/lists/oss-security/2024/05/27/5","http://www.openwall.com/lists/oss-security/2024/05/27/6","http://www.openwall.com/lists/oss-security/2024/07/22/5","https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/","https://security.netapp.com/advisory/ntap-20240531-0002/","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004","https://www.ambionics.io/blog/iconv-cve-2024-2961-p1","https://www.ambionics.io/blog/iconv-cve-2024-2961-p2","https://www.ambionics.io/blog/iconv-cve-2024-2961-p3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2961","description":"The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36221","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36221","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36221","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36221","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"risk":42.497,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36221"},"relatedVulnerabilities":[{"id":"CVE-2020-36221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36221","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36221","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9404","https://bugs.openldap.org/show_bug.cgi?id=9424","https://git.openldap.org/openldap/openldap/-/commit/38ac838e4150c626bbfa0082b7e2cf3a2bb4df31","https://git.openldap.org/openldap/openldap/-/commit/58c1748e81c843c5b6e61648d2a4d1d82b47e842","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36221","description":"An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck)."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36228","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36228","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36228","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36228","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"risk":42.497,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36228"},"relatedVulnerabilities":[{"id":"CVE-2020-36228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36228","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36228","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9427","https://git.openldap.org/openldap/openldap/-/commit/91dccd25c347733b365adc74cb07d074512ed5ad","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36228","description":"An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36221","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36221","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36221","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36221","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"risk":42.497,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36221"},"relatedVulnerabilities":[{"id":"CVE-2020-36221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36221","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36221","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9404","https://bugs.openldap.org/show_bug.cgi?id=9424","https://git.openldap.org/openldap/openldap/-/commit/38ac838e4150c626bbfa0082b7e2cf3a2bb4df31","https://git.openldap.org/openldap/openldap/-/commit/58c1748e81c843c5b6e61648d2a4d1d82b47e842","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36221","description":"An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck)."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36228","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36228","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36228","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36228","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"risk":42.497,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36228"},"relatedVulnerabilities":[{"id":"CVE-2020-36228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36228","cwe":"CWE-191","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36228","date":"2026-10-08","epss":0.84994,"percentile":0.99709}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9427","https://git.openldap.org/openldap/openldap/-/commit/91dccd25c347733b365adc74cb07d074512ed5ad","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36228","description":"An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service."}]},{"artifact":{"id":"839771142f972cee","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/ubuntu/libnghttp2-14@1.30.0-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=nghttp2","type":"deb","version":"1.30.0-1ubuntu1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","SIL-OFL-1.1","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-28182","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nghttp2","version":"1.30.0-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-28182","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-28182","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-28182","date":"2026-10-08","epss":0.8496,"percentile":0.99708}],"risk":42.480000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-28182"},"relatedVulnerabilities":[{"id":"CVE-2024-28182","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28182","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-28182","date":"2026-10-08","epss":0.8496,"percentile":0.99708}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/03/16","https://github.com/nghttp2/nghttp2/commit/00201ecd8f982da3b67d4f6868af72a1b03b14e0","https://github.com/nghttp2/nghttp2/commit/d71a4668c6bead55805d18810d633fbb98315af9","https://github.com/nghttp2/nghttp2/security/advisories/GHSA-x6x3-gv8h-m57q","https://lists.debian.org/debian-lts-announce/2024/04/msg00026.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AGOME6ZXJG7664IPQNVE3DL67E3YP3HY/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J6ZMXUGB66VAXDW5J6QSTHM5ET25FGSA/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXJO2EASHM2OQQLGVDY5ZSO7UVDVHTDK/","https://lists.debian.org/debian-lts-announce/2024/09/msg00041.html","https://www.kb.cert.org/vuls/id/421644"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28182","description":"nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync.  This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability."}]},{"artifact":{"id":"3f92c454a30427fb","cpes":["cpe:2.3:a:org.springframework:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-webmvc","purl":"pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-webmvc-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-webmvc","archiveDigests":[{"value":"652abc943904d67504dc822197868cafaa5e56b5","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-webmvc-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g5vr-rgqm-vf78","versionConstraint":"<=5.3.40 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-webmvc","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-g5vr-rgqm-vf78","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-38819","cwe":"CWE-22","type":"Secondary","source":"security@vmware.com"}],"epss":[{"cve":"CVE-2024-38819","date":"2026-10-08","epss":0.5604,"percentile":0.99027}],"risk":42.03,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-38819","https://spring.io/security/cve-2024-38819","https://github.com/spring-projects/spring-framework/issues/33689","https://github.com/spring-projects/spring-framework/commit/3bfbe30a7814c9ea1556d40df9bd87ddb3ba372d","https://github.com/spring-projects/spring-framework/commit/fb7890d73975a3d9e0763e0926df2bd0a608e87e","https://security.netapp.com/advisory/ntap-20250110-0010"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g5vr-rgqm-vf78","description":"Spring Framework Path Traversal vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-38819","cvss":[{"type":"Secondary","source":"security@vmware.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-38819","cwe":"CWE-22","type":"Secondary","source":"security@vmware.com"}],"epss":[{"cve":"CVE-2024-38819","date":"2026-10-08","epss":0.5604,"percentile":0.99027}],"urls":["https://spring.io/security/cve-2024-38819","https://security.netapp.com/advisory/ntap-20250110-0010/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38819","description":"Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.17"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-1292","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.17 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-1292","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.17"],"available":[{"date":"2022-05-04","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.17"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-1292","date":"2026-10-08","epss":0.82612,"percentile":0.99661}],"risk":41.306,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1292"},"relatedVulnerabilities":[{"id":"CVE-2022-1292","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-1292","date":"2026-10-08","epss":0.82612,"percentile":0.99661}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=548d3f280a6e737673f5b61fce24bb100108dfeb","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23","https://lists.debian.org/debian-lts-announce/2022/05/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VX4KWHPMKYJL6ZLW4M5IU7E5UV5ZWJQU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNU5M7BXMML26G3GPYKFGQYPQDRSNKDD/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220602-0009/","https://security.netapp.com/advisory/ntap-20220729-0004/","https://www.debian.org/security/2022/dsa-5139","https://www.openssl.org/news/secadv/20220503.txt","https://www.oracle.com/security-alerts/cpujul2022.html","https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1292","description":"The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.17"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-1292","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.17 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-1292","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.17"],"available":[{"date":"2022-05-04","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.17"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-1292","date":"2026-10-08","epss":0.82612,"percentile":0.99661}],"risk":41.306,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1292"},"relatedVulnerabilities":[{"id":"CVE-2022-1292","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-1292","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-1292","date":"2026-10-08","epss":0.82612,"percentile":0.99661}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=548d3f280a6e737673f5b61fce24bb100108dfeb","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23","https://lists.debian.org/debian-lts-announce/2022/05/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VX4KWHPMKYJL6ZLW4M5IU7E5UV5ZWJQU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNU5M7BXMML26G3GPYKFGQYPQDRSNKDD/","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220602-0009/","https://security.netapp.com/advisory/ntap-20220729-0004/","https://www.debian.org/security/2022/dsa-5139","https://www.openssl.org/news/secadv/20220503.txt","https://www.oracle.com/security-alerts/cpujul2022.html","https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1292","description":"The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.16+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-34169","versionConstraint":"< 11.0.16+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-34169","fix":{"state":"fixed","versions":["11.0.16+8-0ubuntu1~18.04"],"available":[{"date":"2022-08-04","kind":"advisory","version":"11.0.16+8-0ubuntu1~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-34169","cwe":"CWE-681","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-34169","cwe":"CWE-681","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-34169","date":"2026-10-08","epss":0.81759,"percentile":0.99639}],"risk":40.8795,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-34169"},"relatedVulnerabilities":[{"id":"CVE-2022-34169","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-34169","cwe":"CWE-681","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-34169","cwe":"CWE-681","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-34169","date":"2026-10-08","epss":0.81759,"percentile":0.99639}],"urls":["http://packetstormsecurity.com/files/168186/Xalan-J-XSLTC-Integer-Truncation.html","http://www.openwall.com/lists/oss-security/2022/07/19/5","http://www.openwall.com/lists/oss-security/2022/07/19/6","http://www.openwall.com/lists/oss-security/2022/07/20/2","http://www.openwall.com/lists/oss-security/2022/07/20/3","http://www.openwall.com/lists/oss-security/2022/10/18/2","http://www.openwall.com/lists/oss-security/2022/11/04/8","http://www.openwall.com/lists/oss-security/2022/11/07/2","https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kyw","https://lists.apache.org/thread/2qvl7r43wb4t8p9dd9om1bnkssk07sn8","https://lists.debian.org/debian-lts-announce/2022/10/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB/","https://security.gentoo.org/glsa/202401-25","https://security.netapp.com/advisory/ntap-20220729-0009/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2022/dsa-5188","https://www.debian.org/security/2022/dsa-5192","https://www.debian.org/security/2022/dsa-5256","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-34169","description":"The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan."}]},{"artifact":{"id":"839771142f972cee","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/ubuntu/libnghttp2-14@1.30.0-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=nghttp2","type":"deb","version":"1.30.0-1ubuntu1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","SIL-OFL-1.1","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9513","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nghttp2","version":"1.30.0-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9513","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9513","cwe":"CWE-400","type":"Secondary","source":"cret@cert.org"},{"cve":"CVE-2019-9513","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9513","date":"2026-10-08","epss":0.81556,"percentile":0.99636}],"risk":40.778,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9513"},"relatedVulnerabilities":[{"id":"CVE-2019-9513","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"impactScore":6.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"cret@cert.org","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9513","cwe":"CWE-400","type":"Secondary","source":"cret@cert.org"},{"cve":"CVE-2019-9513","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9513","date":"2026-10-08","epss":0.81556,"percentile":0.99636}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html","https://access.redhat.com/errata/RHSA-2019:2692","https://access.redhat.com/errata/RHSA-2019:2745","https://access.redhat.com/errata/RHSA-2019:2746","https://access.redhat.com/errata/RHSA-2019:2775","https://access.redhat.com/errata/RHSA-2019:2799","https://access.redhat.com/errata/RHSA-2019:2925","https://access.redhat.com/errata/RHSA-2019:2939","https://access.redhat.com/errata/RHSA-2019:2949","https://access.redhat.com/errata/RHSA-2019:2955","https://access.redhat.com/errata/RHSA-2019:2966","https://access.redhat.com/errata/RHSA-2019:3041","https://access.redhat.com/errata/RHSA-2019:3932","https://access.redhat.com/errata/RHSA-2019:3933","https://access.redhat.com/errata/RHSA-2019:3935","https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md","https://kb.cert.org/vuls/id/605641/","https://kc.mcafee.com/corporate/index?page=content&id=SB10296","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JUBYAF6ED3O4XCHQ5C2HYENJLXYXZC4M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZLUYPYY3RX4ZJDWZRJIKSULYRJ4PXW7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPAEC4FWL4UU4LDEGPY5NPALU24FFQD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAZZEVTCN2B4WT6AIBJ7XGYJMBTORJU5/","https://seclists.org/bugtraq/2019/Aug/40","https://seclists.org/bugtraq/2019/Sep/1","https://security.netapp.com/advisory/ntap-20190823-0002/","https://security.netapp.com/advisory/ntap-20190823-0005/","https://support.f5.com/csp/article/K02591030","https://support.f5.com/csp/article/K02591030?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4099-1/","https://www.debian.org/security/2019/dsa-4505","https://www.debian.org/security/2019/dsa-4511","https://www.debian.org/security/2020/dsa-4669","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.synology.com/security/advisory/Synology_SA_19_33"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9513","description":"Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.35"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-344f-f5vg-2jfj","versionConstraint":">=9.0.0,<9.0.35 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-344f-f5vg-2jfj","fix":{"state":"fixed","versions":["9.0.35"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"9.0.35"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9484","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-9484","date":"2026-10-08","epss":0.5552,"percentile":0.99016}],"risk":40.251999999999995,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-9484","https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469@%3Cusers.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/05/msg00020.html","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html","https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2@%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html","http://seclists.org/fulldisclosure/2020/Jun/6","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed@%3Cdev.tomcat.apache.org%3E","https://security.gentoo.org/glsa/202006-21","https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.debian.org/security/2020/dsa-4727","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119@%3Ccommits.tomee.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cusers.tomcat.apache.org%3E","http://www.openwall.com/lists/oss-security/2021/03/01/2","https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c@%3Ccommits.tomee.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c@%3Cdev.tomcat.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/apache/tomcat/commit/3aa8f28db7efb311cdd1b6fe15a9cd3b167a2222.patch","https://github.com/apache/tomcat/commit/bb33048e3f9b4f2b70e4da2e6c4e34ca89023b1b","https://bugzilla.suse.com/show_bug.cgi?id=1171928","https://github.com/apache/tomcat/commit/4785433a226a20df6acbea49296e1ce7e23de453","https://github.com/apache/tomcat/commit/6d66e99ef85da93e4d2c2a536ca51aa3418bfaf4","https://github.com/apache/tomcat/commit/74b105657ffbd1d1de80455f03446c3bbf30d1f5","https://github.com/apache/tomcat/commit/93f0cc403a9210d469afc2bd9cf03ab3251c6f35","https://tomcat.apache.org/security-9.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-7.html","https://tomcat.apache.org/security-10.html","https://security.netapp.com/advisory/ntap-20200528-0005","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ","https://usn.ubuntu.com/4448-1","https://usn.ubuntu.com/4596-1","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-344f-f5vg-2jfj","description":"Potential remote code execution in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2020-9484","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9484","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-9484","date":"2026-10-08","epss":0.5552,"percentile":0.99016}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html","http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html","http://seclists.org/fulldisclosure/2020/Jun/6","http://www.openwall.com/lists/oss-security/2021/03/01/2","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/05/msg00020.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N/","https://security.gentoo.org/glsa/202006-21","https://security.netapp.com/advisory/ntap-20200528-0005/","https://usn.ubuntu.com/4448-1/","https://usn.ubuntu.com/4596-1/","https://www.debian.org/security/2020/dsa-4727","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-9484","description":"When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter=\"null\" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36222","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36222","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36222","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36222","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"risk":38.618,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36222"},"relatedVulnerabilities":[{"id":"CVE-2020-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36222","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36222","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9406","https://bugs.openldap.org/show_bug.cgi?id=9407","https://git.openldap.org/openldap/openldap/-/commit/02dfc32d658fadc25e4040f78e36592f6e1e1ca0","https://git.openldap.org/openldap/openldap/-/commit/6ed057b5b728b50746c869bcc9c1f85d0bbbf6ed","https://git.openldap.org/openldap/openldap/-/commit/6ed057b5b728b50746c869bcc9c1f85d0bbbf6ed.aa","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36222","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36227","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36227","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36227","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36227","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"risk":38.618,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36227"},"relatedVulnerabilities":[{"id":"CVE-2020-36227","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36227","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36227","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9428","https://git.openldap.org/openldap/openldap/-/commit/9d0e8485f3113505743baabf1167e01e4558ccf5","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36227","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36222","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36222","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36222","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36222","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"risk":38.618,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36222"},"relatedVulnerabilities":[{"id":"CVE-2020-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36222","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36222","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9406","https://bugs.openldap.org/show_bug.cgi?id=9407","https://git.openldap.org/openldap/openldap/-/commit/02dfc32d658fadc25e4040f78e36592f6e1e1ca0","https://git.openldap.org/openldap/openldap/-/commit/6ed057b5b728b50746c869bcc9c1f85d0bbbf6ed","https://git.openldap.org/openldap/openldap/-/commit/6ed057b5b728b50746c869bcc9c1f85d0bbbf6ed.aa","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36222","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36227","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36227","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36227","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36227","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"risk":38.618,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36227"},"relatedVulnerabilities":[{"id":"CVE-2020-36227","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36227","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36227","date":"2026-10-08","epss":0.77236,"percentile":0.99545}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9428","https://git.openldap.org/openldap/openldap/-/commit/9d0e8485f3113505743baabf1167e01e4558ccf5","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36227","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.23"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-2650","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.23 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-2650","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.23"],"available":[{"date":"2023-05-30","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.23"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2650","date":"2026-10-08","epss":0.75116,"percentile":0.995}],"risk":37.558,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-2650"},"relatedVulnerabilities":[{"id":"CVE-2023-2650","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2650","date":"2026-10-08","epss":0.75116,"percentile":0.995}],"urls":["http://www.openwall.com/lists/oss-security/2023/05/30/1","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=423a2bc737a908ad0c77bda470b2b59dc879936b","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=853c5e56ee0b8650c73140816bb8b91d6163422c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9e209944b35cf82368071f160a744b6178f9b098","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db779b0e10b047f2585615e0b8f2acdf21f8544a","https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0009","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230703-0001/","https://security.netapp.com/advisory/ntap-20231027-0009/","https://www.debian.org/security/2023/dsa-5417","https://www.openssl.org/news/secadv/20230530.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2650","description":"Issue summary: Processing some specially crafted ASN.1 object identifiers or\ndata containing them may be very slow.\n\nImpact summary: Applications that use OBJ_obj2txt() directly, or use any of\nthe OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message\nsize limit may experience notable to very long delays when processing those\nmessages, which may lead to a Denial of Service.\n\nAn OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers -\nmost of which have no size limit.  OBJ_obj2txt() may be used to translate\nan ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL\ntype ASN1_OBJECT) to its canonical numeric text form, which are the\nsub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by\nperiods.\n\nWhen one of the sub-identifiers in the OBJECT IDENTIFIER is very large\n(these are sizes that are seen as absurdly large, taking up tens or hundreds\nof KiBs), the translation to a decimal number in text may take a very long\ntime.  The time complexity is O(n^2) with 'n' being the size of the\nsub-identifiers in bytes (*).\n\nWith OpenSSL 3.0, support to fetch cryptographic algorithms using names /\nidentifiers in string form was introduced.  This includes using OBJECT\nIDENTIFIERs in canonical numeric text form as identifiers for fetching\nalgorithms.\n\nSuch OBJECT IDENTIFIERs may be received through the ASN.1 structure\nAlgorithmIdentifier, which is commonly used in multiple protocols to specify\nwhat cryptographic algorithm should be used to sign or verify, encrypt or\ndecrypt, or digest passed data.\n\nApplications that call OBJ_obj2txt() directly with untrusted data are\naffected, with any version of OpenSSL.  If the use is for the mere purpose\nof display, the severity is considered low.\n\nIn OpenSSL 3.0 and newer, this affects the subsystems OCSP, PKCS7/SMIME,\nCMS, CMP/CRMF or TS.  It also impacts anything that processes X.509\ncertificates, including simple things like verifying its signature.\n\nThe impact on TLS is relatively low, because all versions of OpenSSL have a\n100KiB limit on the peer's certificate chain.  Additionally, this only\nimpacts clients, or servers that have explicitly enabled client\nauthentication.\n\nIn OpenSSL 1.1.1 and 1.0.2, this only affects displaying diverse objects,\nsuch as X.509 certificates.  This is assumed to not happen in such a way\nthat it would cause a Denial of Service, so these versions are considered\nnot affected by this issue in such a way that it would be cause for concern,\nand the severity is therefore considered low."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.23"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-2650","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.23 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-2650","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.23"],"available":[{"date":"2023-05-30","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.23"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2650","date":"2026-10-08","epss":0.75116,"percentile":0.995}],"risk":37.558,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-2650"},"relatedVulnerabilities":[{"id":"CVE-2023-2650","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2650","date":"2026-10-08","epss":0.75116,"percentile":0.995}],"urls":["http://www.openwall.com/lists/oss-security/2023/05/30/1","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=423a2bc737a908ad0c77bda470b2b59dc879936b","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=853c5e56ee0b8650c73140816bb8b91d6163422c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9e209944b35cf82368071f160a744b6178f9b098","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db779b0e10b047f2585615e0b8f2acdf21f8544a","https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0009","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230703-0001/","https://security.netapp.com/advisory/ntap-20231027-0009/","https://www.debian.org/security/2023/dsa-5417","https://www.openssl.org/news/secadv/20230530.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2650","description":"Issue summary: Processing some specially crafted ASN.1 object identifiers or\ndata containing them may be very slow.\n\nImpact summary: Applications that use OBJ_obj2txt() directly, or use any of\nthe OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message\nsize limit may experience notable to very long delays when processing those\nmessages, which may lead to a Denial of Service.\n\nAn OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers -\nmost of which have no size limit.  OBJ_obj2txt() may be used to translate\nan ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL\ntype ASN1_OBJECT) to its canonical numeric text form, which are the\nsub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by\nperiods.\n\nWhen one of the sub-identifiers in the OBJECT IDENTIFIER is very large\n(these are sizes that are seen as absurdly large, taking up tens or hundreds\nof KiBs), the translation to a decimal number in text may take a very long\ntime.  The time complexity is O(n^2) with 'n' being the size of the\nsub-identifiers in bytes (*).\n\nWith OpenSSL 3.0, support to fetch cryptographic algorithms using names /\nidentifiers in string form was introduced.  This includes using OBJECT\nIDENTIFIERs in canonical numeric text form as identifiers for fetching\nalgorithms.\n\nSuch OBJECT IDENTIFIERs may be received through the ASN.1 structure\nAlgorithmIdentifier, which is commonly used in multiple protocols to specify\nwhat cryptographic algorithm should be used to sign or verify, encrypt or\ndecrypt, or digest passed data.\n\nApplications that call OBJ_obj2txt() directly with untrusted data are\naffected, with any version of OpenSSL.  If the use is for the mere purpose\nof display, the severity is considered low.\n\nIn OpenSSL 3.0 and newer, this affects the subsystems OCSP, PKCS7/SMIME,\nCMS, CMP/CRMF or TS.  It also impacts anything that processes X.509\ncertificates, including simple things like verifying its signature.\n\nThe impact on TLS is relatively low, because all versions of OpenSSL have a\n100KiB limit on the peer's certificate chain.  Additionally, this only\nimpacts clients, or servers that have explicitly enabled client\nauthentication.\n\nIn OpenSSL 1.1.1 and 1.0.2, this only affects displaying diverse objects,\nsuch as X.509 certificates.  This is assumed to not happen in such a way\nthat it would cause a Denial of Service, so these versions are considered\nnot affected by this issue in such a way that it would be cause for concern,\nand the severity is therefore considered low."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.71"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hfrx-6qgj-fp6c","versionConstraint":">=9.0.0-M1,<9.0.71 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hfrx-6qgj-fp6c","fix":{"state":"fixed","versions":["9.0.71"],"available":[{"date":"2024-04-19","kind":"first-observed","version":"9.0.71"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24998","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2023-24998","date":"2026-10-08","epss":0.48788,"percentile":0.98848}],"risk":36.590999999999994,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-24998","https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy","https://github.com/apache/commons-fileupload/commit/e20c04990f7420ca917e96a84cec58b13a1b3d17","https://commons.apache.org/proper/commons-fileupload/security-reports.html","http://www.openwall.com/lists/oss-security/2023/05/22/1","https://security.gentoo.org/glsa/202305-37","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://www.debian.org/security/2023/dsa-5522","https://github.com/apache/tomcat/commit/8a2285f13affa961cc65595aad999db5efae45ce","https://github.com/apache/tomcat/commit/9ca96c8c1eba86c0aaa2e6be581ba2a7d4d4ae6e","https://github.com/apache/tomcat/commit/cf77cc545de0488fb89e24294151504a7432df74","https://github.com/apache/tomcat/commit/d53d8e7f77042cc32a3b98f589496a1ef5088e38","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-9.html","https://github.com/search?q=repo%3Aapache%2Ftomcat+util.http+path%3A%2F%5Eres%5C%2Fbnd%5C%2F%2F&type=code","https://security.netapp.com/advisory/ntap-20230302-0013","https://lists.debian.org/debian-lts-announce/2025/07/msg00008.html","https://security.netapp.com/advisory/ntap-20241108-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hfrx-6qgj-fp6c","description":"Apache Commons FileUpload denial of service vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2023-24998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24998","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2023-24998","date":"2026-10-08","epss":0.48788,"percentile":0.98848}],"urls":["http://www.openwall.com/lists/oss-security/2023/05/22/1","https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://security.gentoo.org/glsa/202305-37","https://www.debian.org/security/2023/dsa-5522","https://lists.debian.org/debian-lts-announce/2025/07/msg00008.html","https://security.netapp.com/advisory/ntap-20230302-0013/","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24998","description":"Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.\n\n\n\n\nNote that, like all of the file upload limits, the\n          new configuration option (FileUploadBase#setFileCountMax) is not\n          enabled by default and must be explicitly configured."}]},{"artifact":{"id":"7a6dcfb98884d7c9","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1ubuntu0.3?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1ubuntu0.3","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2025-6965","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-6965","cwe":"CWE-197","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-6965","date":"2026-10-08","epss":0.71394,"percentile":0.99401}],"risk":35.697,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-6965"},"relatedVulnerabilities":[{"id":"CVE-2025-6965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.3,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Green","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6965","cwe":"CWE-197","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-6965","date":"2026-10-08","epss":0.71394,"percentile":0.99401}],"urls":["https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8","http://seclists.org/fulldisclosure/2025/Sep/49","http://seclists.org/fulldisclosure/2025/Sep/53","http://seclists.org/fulldisclosure/2025/Sep/56","http://seclists.org/fulldisclosure/2025/Sep/57","http://seclists.org/fulldisclosure/2025/Sep/58","http://www.openwall.com/lists/oss-security/2025/09/06/1","https://cert-portal.siemens.com/productcert/html/ssa-225816.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6965","description":"There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-29155","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-29155","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.11"],"available":[{"date":"2022-05-17","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-29155","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29155","date":"2026-10-08","epss":0.64487,"percentile":0.99221}],"risk":32.243500000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-29155"},"relatedVulnerabilities":[{"id":"CVE-2022-29155","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-29155","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29155","date":"2026-10-08","epss":0.64487,"percentile":0.99221}],"urls":["https://bugs.openldap.org/show_bug.cgi?id=9815","https://lists.debian.org/debian-lts-announce/2022/05/msg00032.html","https://security.netapp.com/advisory/ntap-20220609-0007/","https://www.debian.org/security/2022/dsa-5140"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-29155","description":"In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-29155","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-29155","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.11"],"available":[{"date":"2022-05-17","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-29155","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29155","date":"2026-10-08","epss":0.64487,"percentile":0.99221}],"risk":32.243500000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-29155"},"relatedVulnerabilities":[{"id":"CVE-2022-29155","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-29155","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29155","date":"2026-10-08","epss":0.64487,"percentile":0.99221}],"urls":["https://bugs.openldap.org/show_bug.cgi?id=9815","https://lists.debian.org/debian-lts-announce/2022/05/msg00032.html","https://security.netapp.com/advisory/ntap-20220609-0007/","https://www.debian.org/security/2022/dsa-5140"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-29155","description":"In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping."}]},{"artifact":{"id":"fe0e460326107a0f","cpes":["cpe:2.3:a:libcups2:libcups2:2.2.7-1ubuntu2.7:*:*:*:*:*:*:*"],"name":"libcups2","purl":"pkg:deb/ubuntu/libcups2@2.2.7-1ubuntu2.7?arch=amd64&distro=ubuntu-18.04&upstream=cups","type":"deb","version":"2.2.7-1ubuntu2.7","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2.0","LGPL-2","LGPL-2.0","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-47175","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cups","version":"2.2.7-1ubuntu2.7"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-47175","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-47175","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-47175","date":"2026-10-08","epss":0.63607,"percentile":0.99198}],"risk":31.8035,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-47175"},"relatedVulnerabilities":[{"id":"CVE-2024-47175","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-47175","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-47175","date":"2026-10-08","epss":0.63607,"percentile":0.99198}],"urls":["https://github.com/OpenPrinting/cups-browsed/security/advisories/GHSA-rj88-6mr5-rcw8","https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-p9rh-jxmq-gq47","https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-w63j-6g73-wmg5","https://github.com/OpenPrinting/libppd/security/advisories/GHSA-7xfx-47qg-grp6","https://www.cups.org","https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I","http://www.openwall.com/lists/oss-security/2024/09/27/3","https://github.com/OpenPrinting/libppd/commit/d681747ebf12602cb426725eb8ce2753211e2477","https://lists.debian.org/debian-lts-announce/2024/09/msg00047.html","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0016","https://security.netapp.com/advisory/ntap-20241011-0001/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47175","description":"CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPrinterAttributes5`, can result in user controlled input and ultimately code execution via Foomatic. This vulnerability can be part of an exploit chain leading to remote code execution (RCE), as described in CVE-2024-47176."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-27212","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-27212","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.10"],"available":[{"date":"2021-02-22","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.10"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-27212","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-27212","date":"2026-10-08","epss":0.63321,"percentile":0.9919}],"risk":31.660500000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-27212"},"relatedVulnerabilities":[{"id":"CVE-2021-27212","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-27212","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-27212","date":"2026-10-08","epss":0.63321,"percentile":0.9919}],"urls":["https://bugs.openldap.org/show_bug.cgi?id=9454","https://git.openldap.org/openldap/openldap/-/commit/3539fc33212b528c56b716584f2c2994af7c30b0","https://git.openldap.org/openldap/openldap/-/commit/9badb73425a67768c09bcaed1a9c26c684af6c30","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00035.html","https://security.netapp.com/advisory/ntap-20210319-0005/","https://www.debian.org/security/2021/dsa-4860"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-27212","description":"In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-27212","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-27212","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.10"],"available":[{"date":"2021-02-22","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.10"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-27212","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-27212","date":"2026-10-08","epss":0.63321,"percentile":0.9919}],"risk":31.660500000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-27212"},"relatedVulnerabilities":[{"id":"CVE-2021-27212","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-27212","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-27212","date":"2026-10-08","epss":0.63321,"percentile":0.9919}],"urls":["https://bugs.openldap.org/show_bug.cgi?id=9454","https://git.openldap.org/openldap/openldap/-/commit/3539fc33212b528c56b716584f2c2994af7c30b0","https://git.openldap.org/openldap/openldap/-/commit/9badb73425a67768c09bcaed1a9c26c684af6c30","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00035.html","https://security.netapp.com/advisory/ntap-20210319-0005/","https://www.debian.org/security/2021/dsa-4860"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-27212","description":"In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime."}]},{"artifact":{"id":"d12e5c57a00d0dbc","cpes":["cpe:2.3:a:org.springframework:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-web","purl":"pkg:maven/org.springframework/spring-web@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-web-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-web","archiveDigests":[{"value":"d5b064196dc014519e751df549b4cc6a753fb191","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-web-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"6.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4wrc-f8pq-fpqp","versionConstraint":"<6.0.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-web","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4wrc-f8pq-fpqp","fix":{"state":"fixed","versions":["6.0.0"],"available":[{"date":"2022-12-10","kind":"first-observed","version":"6.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1000027","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-1000027","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-1000027","date":"2026-10-08","epss":0.33179,"percentile":0.98331}],"risk":31.18826,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2016-1000027","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027","https://security-tracker.debian.org/tracker/CVE-2016-1000027","https://www.tenable.com/security/research/tra-2016-20","https://github.com/spring-projects/spring-framework/issues/24434","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-1231625331","https://github.com/spring-projects/spring-framework/commit/5cbe90b2cd91b866a5a9586e460f311860e11cfa","https://support.contrastsecurity.com/hc/en-us/articles/4402400830612-Spring-web-Java-Deserialization-CVE-2016-1000027","https://github.com/spring-projects/spring-framework/issues/21680","https://github.com/spring-projects/spring-framework/commit/2b051b8b321768a4cfef83077db65c6328ffd60f","https://jira.spring.io/browse/SPR-17143?redirect=false","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525","https://security.netapp.com/advisory/ntap-20230420-0009/","https://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-now"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4wrc-f8pq-fpqp","description":"Pivotal Spring Framework contains unsafe Java deserialization methods"},"relatedVulnerabilities":[{"id":"CVE-2016-1000027","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-1000027","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-1000027","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-1000027","date":"2026-10-08","epss":0.33179,"percentile":0.98331}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417","https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525","https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000027.json","https://security-tracker.debian.org/tracker/CVE-2016-1000027","https://security.netapp.com/advisory/ntap-20230420-0009/","https://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-now","https://www.tenable.com/security/research/tra-2016-20"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000027","description":"Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data."}]},{"artifact":{"id":"839771142f972cee","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/ubuntu/libnghttp2-14@1.30.0-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=nghttp2","type":"deb","version":"1.30.0-1ubuntu1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","SIL-OFL-1.1","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9511","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nghttp2","version":"1.30.0-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9511","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9511","cwe":"CWE-400","type":"Secondary","source":"cret@cert.org"},{"cve":"CVE-2019-9511","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9511","date":"2026-10-08","epss":0.59547,"percentile":0.99105}],"risk":29.773500000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9511"},"relatedVulnerabilities":[{"id":"CVE-2019-9511","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"impactScore":6.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"cret@cert.org","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9511","cwe":"CWE-400","type":"Secondary","source":"cret@cert.org"},{"cve":"CVE-2019-9511","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9511","date":"2026-10-08","epss":0.59547,"percentile":0.99105}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html","https://access.redhat.com/errata/RHSA-2019:2692","https://access.redhat.com/errata/RHSA-2019:2745","https://access.redhat.com/errata/RHSA-2019:2746","https://access.redhat.com/errata/RHSA-2019:2775","https://access.redhat.com/errata/RHSA-2019:2799","https://access.redhat.com/errata/RHSA-2019:2925","https://access.redhat.com/errata/RHSA-2019:2939","https://access.redhat.com/errata/RHSA-2019:2949","https://access.redhat.com/errata/RHSA-2019:2955","https://access.redhat.com/errata/RHSA-2019:2966","https://access.redhat.com/errata/RHSA-2019:3041","https://access.redhat.com/errata/RHSA-2019:3932","https://access.redhat.com/errata/RHSA-2019:3933","https://access.redhat.com/errata/RHSA-2019:3935","https://access.redhat.com/errata/RHSA-2019:4018","https://access.redhat.com/errata/RHSA-2019:4019","https://access.redhat.com/errata/RHSA-2019:4020","https://access.redhat.com/errata/RHSA-2019:4021","https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md","https://kb.cert.org/vuls/id/605641/","https://kc.mcafee.com/corporate/index?page=content&id=SB10296","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JUBYAF6ED3O4XCHQ5C2HYENJLXYXZC4M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZLUYPYY3RX4ZJDWZRJIKSULYRJ4PXW7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPAEC4FWL4UU4LDEGPY5NPALU24FFQD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAZZEVTCN2B4WT6AIBJ7XGYJMBTORJU5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHTKU7YQ5EEP2XNSAV4M4VJ7QCBOJMOD/","https://seclists.org/bugtraq/2019/Aug/40","https://seclists.org/bugtraq/2019/Sep/1","https://security.netapp.com/advisory/ntap-20190823-0002/","https://security.netapp.com/advisory/ntap-20190823-0005/","https://support.f5.com/csp/article/K02591030","https://support.f5.com/csp/article/K02591030?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4099-1/","https://www.debian.org/security/2019/dsa-4505","https://www.debian.org/security/2019/dsa-4511","https://www.debian.org/security/2020/dsa-4669","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.synology.com/security/advisory/Synology_SA_19_33"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9511","description":"Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both."}]},{"artifact":{"id":"c1103d6297198441","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-0ubuntu2:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.2.11.dfsg-0ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=zlib","type":"deb","version":"1:1.2.11.dfsg-0ubuntu2","language":"","licenses":["sha256:176de9c848d59ea736369969db73dcbe025da6360dfba52ad034b52d9616b7c3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:1.2.11.dfsg-0ubuntu2.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-25032","versionConstraint":"< 1:1.2.11.dfsg-0ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"zlib","version":"1:1.2.11.dfsg-0ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-25032","fix":{"state":"fixed","versions":["1:1.2.11.dfsg-0ubuntu2.1"],"available":[{"date":"2022-03-30","kind":"advisory","version":"1:1.2.11.dfsg-0ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-25032","date":"2026-10-08","epss":0.51733,"percentile":0.98922}],"risk":25.8665,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-25032"},"relatedVulnerabilities":[{"id":"CVE-2018-25032","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-25032","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-25032","date":"2026-10-08","epss":0.51733,"percentile":0.98922}],"urls":["http://seclists.org/fulldisclosure/2022/May/33","http://seclists.org/fulldisclosure/2022/May/35","http://seclists.org/fulldisclosure/2022/May/38","http://www.openwall.com/lists/oss-security/2022/03/25/2","http://www.openwall.com/lists/oss-security/2022/03/26/1","https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf","https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531","https://github.com/madler/zlib/compare/v1.2.11...v1.2.12","https://github.com/madler/zlib/issues/605","https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html","https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html","https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/","https://security.gentoo.org/glsa/202210-42","https://security.netapp.com/advisory/ntap-20220526-0009/","https://security.netapp.com/advisory/ntap-20220729-0004/","https://support.apple.com/kb/HT213255","https://support.apple.com/kb/HT213256","https://support.apple.com/kb/HT213257","https://www.debian.org/security/2022/dsa-5111","https://www.openwall.com/lists/oss-security/2022/03/24/1","https://www.openwall.com/lists/oss-security/2022/03/28/1","https://www.openwall.com/lists/oss-security/2022/03/28/3","https://www.oracle.com/security-alerts/cpujul2022.html","https://cert-portal.siemens.com/productcert/html/ssa-333517.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-419740.html","https://cert-portal.siemens.com/productcert/html/ssa-470355.html","https://cert-portal.siemens.com/productcert/html/ssa-565386.html","https://cert-portal.siemens.com/productcert/html/ssa-942865.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-25032","description":"zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-25236","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-25236","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-25236","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25236","cwe":"CWE-668","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25236","date":"2026-10-08","epss":0.34174,"percentile":0.9837}],"risk":25.6305,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-25236"},"relatedVulnerabilities":[{"id":"CVE-2022-25236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25236","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25236","cwe":"CWE-668","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25236","date":"2026-10-08","epss":0.34174,"percentile":0.9837}],"urls":["http://packetstormsecurity.com/files/167238/Zoom-XMPP-Stanza-Smuggling-Remote-Code-Execution.html","http://www.openwall.com/lists/oss-security/2022/02/19/1","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/561","https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220303-0008/","https://www.debian.org/security/2022/dsa-5085","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25236","description":"xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.98"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5j33-cvvr-w245","versionConstraint":">=9.0.0.M1,<9.0.98 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5j33-cvvr-w245","fix":{"state":"fixed","versions":["9.0.98"],"available":[{"date":"2024-12-27","kind":"first-observed","version":"9.0.98"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-50379","cwe":"CWE-367","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-50379","date":"2026-10-08","epss":0.31824,"percentile":0.98263}],"risk":25.459200000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-50379","https://lists.apache.org/thread/y6lj6q1xnp822g6ro70tn19sgtjmr80r","https://github.com/apache/tomcat/commit/05ddeeaa54df1e2dc427d0164bedd6b79f78d81f","https://github.com/apache/tomcat/commit/43b507ebac9d268b1ea3d908e296cc6e46795c00","https://github.com/apache/tomcat/commit/631500b0c9b2a2a2abb707e3de2e10a5936e5d41","https://github.com/apache/tomcat/commit/684247ae85fa633b9197b32391de59fc54703842","https://github.com/apache/tomcat/commit/8554f6b1722b33a2ce8b0a3fad37825f3a75f2d2","https://github.com/apache/tomcat/commit/cc7a98b57c6dc1df21979fcff94a36e068f4456c","https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.34","https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.2","https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.98","http://www.openwall.com/lists/oss-security/2024/12/17/4","http://www.openwall.com/lists/oss-security/2024/12/18/2","https://security.netapp.com/advisory/ntap-20250103-0003","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5j33-cvvr-w245","description":"Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-50379","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-50379","cwe":"CWE-367","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-50379","date":"2026-10-08","epss":0.31824,"percentile":0.98263}],"urls":["https://lists.apache.org/thread/y6lj6q1xnp822g6ro70tn19sgtjmr80r","http://www.openwall.com/lists/oss-security/2024/12/17/4","http://www.openwall.com/lists/oss-security/2024/12/18/2","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html","https://security.netapp.com/advisory/ntap-20250103-0003/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50379","description":"Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration).\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3712","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3712","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.13"],"available":[{"date":"2021-08-24","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3712","date":"2026-10-08","epss":0.50445,"percentile":0.98887}],"risk":25.222499999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3712"},"relatedVulnerabilities":[{"id":"CVE-2021-3712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3712","date":"2026-10-08","epss":0.50445,"percentile":0.98887}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/26/2","https://cert-portal.siemens.com/productcert/pdf/ssa-244969.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=94d23fcff9b2a7a8368dfe52214d5c2569882c11","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ccb0a11145ee72b042d10593a64eaf9e8a55ec12","https://kc.mcafee.com/corporate/index?page=content&id=SB10366","https://lists.apache.org/thread.html/r18995de860f0e63635f3008fd2a6aca82394249476d21691e7c59c9e%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad5d9f83f0d11fb3f8bb148d179b8a9ad7c6a17f18d70e5805a713d1%40%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/09/msg00014.html","https://lists.debian.org/debian-lts-announce/2021/09/msg00021.html","https://security.gentoo.org/glsa/202209-02","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20210827-0010/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4963","https://www.openssl.org/news/secadv/20210824.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-16","https://www.tenable.com/security/tns-2022-02","https://cert-portal.siemens.com/productcert/html/ssa-019200.html","https://cert-portal.siemens.com/productcert/html/ssa-028723.html","https://cert-portal.siemens.com/productcert/html/ssa-244969.html","https://cert-portal.siemens.com/productcert/html/ssa-389290.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3712","description":"ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own \"d2i\" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the \"data\" and \"length\" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the \"data\" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3712","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3712","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.13"],"available":[{"date":"2021-08-24","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3712","date":"2026-10-08","epss":0.50445,"percentile":0.98887}],"risk":25.222499999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3712"},"relatedVulnerabilities":[{"id":"CVE-2021-3712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3712","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3712","date":"2026-10-08","epss":0.50445,"percentile":0.98887}],"urls":["http://www.openwall.com/lists/oss-security/2021/08/26/2","https://cert-portal.siemens.com/productcert/pdf/ssa-244969.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=94d23fcff9b2a7a8368dfe52214d5c2569882c11","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ccb0a11145ee72b042d10593a64eaf9e8a55ec12","https://kc.mcafee.com/corporate/index?page=content&id=SB10366","https://lists.apache.org/thread.html/r18995de860f0e63635f3008fd2a6aca82394249476d21691e7c59c9e%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rad5d9f83f0d11fb3f8bb148d179b8a9ad7c6a17f18d70e5805a713d1%40%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/09/msg00014.html","https://lists.debian.org/debian-lts-announce/2021/09/msg00021.html","https://security.gentoo.org/glsa/202209-02","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20210827-0010/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4963","https://www.openssl.org/news/secadv/20210824.txt","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-16","https://www.tenable.com/security/tns-2022-02","https://cert-portal.siemens.com/productcert/html/ssa-019200.html","https://cert-portal.siemens.com/productcert/html/ssa-028723.html","https://cert-portal.siemens.com/productcert/html/ssa-244969.html","https://cert-portal.siemens.com/productcert/html/ssa-389290.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3712","description":"ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own \"d2i\" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the \"data\" and \"length\" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the \"data\" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4w82-r329-3q67","versionConstraint":">=2.9.0,<=2.9.10.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4w82-r329-3q67","fix":{"state":"fixed","versions":["2.9.10.3"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8840","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8840","date":"2026-10-08","epss":0.26587,"percentile":0.97974}],"risk":24.991780000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-8840","https://github.com/FasterXML/jackson-databind/issues/2620","https://github.com/FasterXML/jackson-databind/commit/914e7c9f2cb8ce66724bf26a72adc7e958992497","https://lists.apache.org/thread.html/r078e68a926ea6be12e8404e47f45aabf04bb4668e8265c0de41db6db@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r319f19c74e06c201b9d4e8b282a4e4b2da6dcda022fb46f007dd00d3@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r3539bd3a377991217d724879d239e16e86001c54160076408574e1da@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r3d20a2660b36551fd8257d479941782af4a7169582449fac1704bde2@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r428d068b2a4923f1a5a4f5fc6381b95205cfe7620169d16db78e9c71@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r46bebdeb59b8b7212d63a010ca445a9f5c4e9d64dcf693cab6f399d3@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r6fdd4c61a09a0c89f581b4ddb3dc6f154ab0c705fcfd0a7358b2e4e5@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8170007fd9b263d65b37d92a7b5d7bc357aedbb113a32838bc4a9485@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9ecf211c22760b00967ebe158c6ed7dba9142078e2a630ab8904a5b7@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rac5ee5d686818be7e7c430d35108ee01a88aae54f832d32f62431fd1@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb43f9a65150948a6bebd3cb77ee3e105d40db2820fd547528f4e7f89@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb5eedf90ba3633e171a2ffdfe484651c9490dc5df74c8a29244cbc0e@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdf8d389271a291dde3b2f99c36918d6cb1e796958af626cc140fee23@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re7326b8655eab931f2a9ce074fd9a1a51b5db11456bee9b48e1e170c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re8ae2670ec456ef1c5a2a661a2838ab2cd00e9efa1e88c069f546f21@%3Ccommits.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html","https://lists.apache.org/thread.html/r65ee95fa09c831843bac81eaa582fdddc2b6119912a72d1c83a9b882@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r1c09b9551f6953dbeca190a4c4b78198cdbb9825fce36f96fe3d8218@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r1efc776fc6ce3387593deaa94bbdd296733b1b01408a39c8d1ab9e0e@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r2fa8046bd47fb407ca09b5107a80fa6147ba4ebe879caae5c98b7657@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r446646c5588b10f5e02409ad580b12f314869009cdfbf844ca395cec@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r5d8bea8e9d17b6efcf4a0e4e194e91ef46a99f505777a31a60da2b38@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r7762d69e85c58d6948823424017ef4c08f47de077644277fa18cc116@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r7e5c10534ed06bf805473ac85e8412fe3908a8fa4cabf5027bf11220@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8e96c340004b7898cad3204ea51280ef6e4b553a684e1452bf1b18b1@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r94930e39b60fff236160c1c4110fe884dc093044b067aa5fc98d7ee1@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r9e59ebaf76fd00b2fa3ff5ebf18fe075ca9f4376216612c696f76718@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/ra275f29615f35d5b40106d1582a41e5388b2a5131564e9e01a572987@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rb73708bf714ed6dbc1212da082e7703e586077f0c92f3940b2e82caf@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rb99c7321eba5d4c907beec46675d52827528b738cfafd48eb4d862f1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc717fd6c65190f4e592345713f9ef0723fb7d71f624caa2a17caa26a@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rcc72b497e3dff2dc62ec9b89ceb90bc4e1b14fc56c3c252a6fcbb013@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rdea588d4a0ebf9cb7ce8c3a8f18d0d306507c4f8ba178dd3d20207b8@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rdf311f13e6356297e0ffe74397fdd25a3687b0a16e687c3ff5b834d8@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rf28ab6f224b48452afd567dfffb705fbda0fdbbf6535f6bc69d47e91@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rfc1ccfe89332155b72ce17f13a2701d3e7b9ec213324ceb90e79a28a@%3Cdev.ranger.apache.org%3E","https://security.netapp.com/advisory/ntap-20200327-0002/","https://www.oracle.com/security-alerts/cpuapr2020.html","http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200610-01-fastjason-en","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/74aba4042fce35ee0b91bd2847e788c10040d78b","https://github.com/FasterXML/jackson-databind/commit/9bb52c7122271df75435ec7e66ecf6b02b1ee14f"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4w82-r329-3q67","description":"Deserialization of Untrusted Data in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-8840","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8840","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8840","date":"2026-10-08","epss":0.26587,"percentile":0.97974}],"urls":["http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200610-01-fastjason-en","https://github.com/FasterXML/jackson-databind/issues/2620","https://lists.apache.org/thread.html/r078e68a926ea6be12e8404e47f45aabf04bb4668e8265c0de41db6db%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r1c09b9551f6953dbeca190a4c4b78198cdbb9825fce36f96fe3d8218%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r1efc776fc6ce3387593deaa94bbdd296733b1b01408a39c8d1ab9e0e%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r2fa8046bd47fb407ca09b5107a80fa6147ba4ebe879caae5c98b7657%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r319f19c74e06c201b9d4e8b282a4e4b2da6dcda022fb46f007dd00d3%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r3539bd3a377991217d724879d239e16e86001c54160076408574e1da%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r3d20a2660b36551fd8257d479941782af4a7169582449fac1704bde2%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r428d068b2a4923f1a5a4f5fc6381b95205cfe7620169d16db78e9c71%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r446646c5588b10f5e02409ad580b12f314869009cdfbf844ca395cec%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r46bebdeb59b8b7212d63a010ca445a9f5c4e9d64dcf693cab6f399d3%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5d8bea8e9d17b6efcf4a0e4e194e91ef46a99f505777a31a60da2b38%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r65ee95fa09c831843bac81eaa582fdddc2b6119912a72d1c83a9b882%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r6fdd4c61a09a0c89f581b4ddb3dc6f154ab0c705fcfd0a7358b2e4e5%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7762d69e85c58d6948823424017ef4c08f47de077644277fa18cc116%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r7e5c10534ed06bf805473ac85e8412fe3908a8fa4cabf5027bf11220%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8170007fd9b263d65b37d92a7b5d7bc357aedbb113a32838bc4a9485%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8e96c340004b7898cad3204ea51280ef6e4b553a684e1452bf1b18b1%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r94930e39b60fff236160c1c4110fe884dc093044b067aa5fc98d7ee1%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r9e59ebaf76fd00b2fa3ff5ebf18fe075ca9f4376216612c696f76718%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r9ecf211c22760b00967ebe158c6ed7dba9142078e2a630ab8904a5b7%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra275f29615f35d5b40106d1582a41e5388b2a5131564e9e01a572987%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rac5ee5d686818be7e7c430d35108ee01a88aae54f832d32f62431fd1%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb43f9a65150948a6bebd3cb77ee3e105d40db2820fd547528f4e7f89%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb5eedf90ba3633e171a2ffdfe484651c9490dc5df74c8a29244cbc0e%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb73708bf714ed6dbc1212da082e7703e586077f0c92f3940b2e82caf%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rb99c7321eba5d4c907beec46675d52827528b738cfafd48eb4d862f1%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc717fd6c65190f4e592345713f9ef0723fb7d71f624caa2a17caa26a%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rcc72b497e3dff2dc62ec9b89ceb90bc4e1b14fc56c3c252a6fcbb013%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rdea588d4a0ebf9cb7ce8c3a8f18d0d306507c4f8ba178dd3d20207b8%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rdf311f13e6356297e0ffe74397fdd25a3687b0a16e687c3ff5b834d8%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rdf8d389271a291dde3b2f99c36918d6cb1e796958af626cc140fee23%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re7326b8655eab931f2a9ce074fd9a1a51b5db11456bee9b48e1e170c%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re8ae2670ec456ef1c5a2a661a2838ab2cd00e9efa1e88c069f546f21%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf28ab6f224b48452afd567dfffb705fbda0fdbbf6535f6bc69d47e91%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rfc1ccfe89332155b72ce17f13a2701d3e7b9ec213324ceb90e79a28a%40%3Cdev.ranger.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html","https://security.netapp.com/advisory/ntap-20200327-0002/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8840","description":"FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mph4-vhrx-mv67","versionConstraint":">=2.9.0,<2.9.9.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mph4-vhrx-mv67","fix":{"state":"fixed","versions":["2.9.9.1"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12384","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12384","date":"2026-10-08","epss":0.45205,"percentile":0.98755}],"risk":24.636725000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-12384","https://doyensec.com/research.html","https://github.com/FasterXML/jackson-databind/compare/74b90a4...a977aad","https://lists.debian.org/debian-lts-announce/2019/06/msg00019.html","https://access.redhat.com/errata/RHSA-2019:1820","https://access.redhat.com/errata/RHSA-2019:2720","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2019:4352","https://blog.doyensec.com/2019/07/22/jackson-gadgets.html","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/e0733058c0366b703e6757d8d2a7a04b943581f659e9c271f0841dfe@%3Cnotifications.geode.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://seclists.org/bugtraq/2019/Oct/6","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/issues/2334","https://github.com/FasterXML/jackson-databind/commit/c9ef4a10d6f6633cf470d6a469514b68fa2be234","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC","https://security.netapp.com/advisory/ntap-20190703-0002"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mph4-vhrx-mv67","description":"Deserialization of Untrusted Data in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-12384","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12384","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12384","date":"2026-10-08","epss":0.45205,"percentile":0.98755}],"urls":["https://access.redhat.com/errata/RHSA-2019:1820","https://access.redhat.com/errata/RHSA-2019:2720","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2019:4352","https://blog.doyensec.com/2019/07/22/jackson-gadgets.html","https://doyensec.com/research.html","https://github.com/FasterXML/jackson-databind/compare/74b90a4...a977aad","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef%40%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/e0733058c0366b703e6757d8d2a7a04b943581f659e9c271f0841dfe%40%3Cnotifications.geode.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20190703-0002/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12384","description":"FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.106"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h3gc-qfqq-6h8f","versionConstraint":">=9.0.0.M1,<=9.0.105 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h3gc-qfqq-6h8f","fix":{"state":"fixed","versions":["9.0.106"],"available":[{"date":"2025-06-17","kind":"first-observed","version":"9.0.106"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48988","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48988","date":"2026-10-08","epss":0.30515,"percentile":0.982}],"risk":23.801699999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48988","https://lists.apache.org/thread/nzkqsok8t42qofgqfmck536mtyzygp18","https://github.com/apache/tomcat/commit/2b0ab14fb55d4edc896e5f1817f2ab76f714ae5e","https://github.com/apache/tomcat/commit/cdde8e655bc1c5c60a07efd216251d77c52fd7f6","https://github.com/apache/tomcat/commit/ee8042ffce4cb9324dfd79efda5984f37bbb6910","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-9.html","http://www.openwall.com/lists/oss-security/2025/06/16/1","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h3gc-qfqq-6h8f","description":"Apache Tomcat - DoS in multipart upload"},"relatedVulnerabilities":[{"id":"CVE-2025-48988","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48988","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48988","date":"2026-10-08","epss":0.30515,"percentile":0.982}],"urls":["https://lists.apache.org/thread/nzkqsok8t42qofgqfmck536mtyzygp18","http://www.openwall.com/lists/oss-security/2025/06/16/1","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48988","description":"Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue."}]},{"artifact":{"id":"c248a20b3cb2033b","cpes":["cpe:2.3:a:org.springframework:spring-expression:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_expression:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-expression:spring-expression:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-expression:spring_expression:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_expression:spring-expression:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_expression:spring_expression:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-expression:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_expression:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-expression:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_expression:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-expression","purl":"pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-expression-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-expression","archiveDigests":[{"value":"ac6a616451129e717979f18d2bff40528698a46e","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-expression-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.20.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-558x-2xjg-6232","versionConstraint":"<5.2.20.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-expression","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-558x-2xjg-6232","fix":{"state":"fixed","versions":["5.2.20.RELEASE"],"available":[{"date":"2023-03-29","kind":"first-observed","version":"5.2.20.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22950","cwe":"CWE-770","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22950","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22950","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"risk":20.746575,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22950","https://tanzu.vmware.com/security/cve-2022-22950","https://github.com/spring-projects/spring-framework/issues/28145","https://github.com/spring-projects/spring-framework/issues/28257","https://github.com/spring-projects/spring-framework/commit/83ac65915871067c39a4fb255e0d484c785c0c11","https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE","https://github.com/spring-projects/spring-framework/releases/tag/v5.3.17"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-558x-2xjg-6232","description":"Allocation of Resources Without Limits or Throttling in Spring Framework"},"relatedVulnerabilities":[{"id":"CVE-2022-22950","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22950","cwe":"CWE-770","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22950","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22950","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"urls":["https://tanzu.vmware.com/security/cve-2022-22950"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22950","description":"n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition."}]},{"artifact":{"id":"2a658e44e9176fca","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.25:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.25","type":"java-archive","version":"1.25","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/snakeyaml-1.25.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"8b6e01ef661d8378ae6dd7b511a7f2a33fae1421","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/snakeyaml-1.25.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rvwf-54qp-4r6v","versionConstraint":"<1.26 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.25"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rvwf-54qp-4r6v","fix":{"state":"fixed","versions":["1.26"],"available":[{"date":"2021-06-05","kind":"first-observed","version":"1.26"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18640","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18640","date":"2026-10-08","epss":0.26723,"percentile":0.97984}],"risk":20.04225,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2017-18640","https://bitbucket.org/asomov/snakeyaml/commits/da11ddbd91c1f8392ea932b37fa48110fa54ed8c","https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-preventing-billion","https://bitbucket.org/asomov/snakeyaml/wiki/Billion%20laughs%20attack","https://bitbucket.org/asomov/snakeyaml/wiki/Changes","https://lists.apache.org/thread.html/r1058e7646988394de6a3fd0857ea9b1ee0de14d7bb28fee5ff782457@%3Ccommits.atlas.apache.org%3E","https://lists.apache.org/thread.html/r154090b871cf96d985b90864442d84eb027c72c94bc3f0a5727ba2d1@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r1703a402f30c8a2ee409f8c6f393e95a63f8c952cc9ee5bf9dd586dc@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r191ceadb1b883357384981848dfa5235cb02a90070c553afbaf9b3d9@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r1aab47b48a757c70e40fc0bcb1fcf1a3951afa6a17aee7cd66cf79f8@%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r1dfac8b6a7097bcb4979402bbb6e2f8c36d0d9001e3018717eb22b7e@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r1ffce2ed3017e9964f03ad2c539d69e49144fc8e9bf772d641612f98@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r20350031c60a77b45e0eded33e9b3e9cb0cbfc5e24e1c63bf264df12@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r22ac2aa053b7d9c6b75a49db78125c9316499668d0f4a044f3402e2f@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r28c9009a48d52cf448f8b02cd823da0f8601d2dff4d66f387a35f1e0@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r2a5b84fdf59042dc398497e914b5bb1aed77328320b1438144ae1953@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r2b05744c0c2867daa5d1a96832965b7d6220328b0ead06c22a6e7854@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r2db207a2431a5e9e95e899858ab1f5eabd9bcc790a6ca7193ae07e94@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r436988d2cfe8a770ae361c82b181c5b2bf48a249bad84d8a55a3b46e@%3Cdev.phoenix.apache.org%3E","https://lists.apache.org/thread.html/r4c682fb8cf69dd14162439656a6ebdf42ea6ad0e4edba95907ea3f14@%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r4d7f37da1bc2df90a5a0f56eb7629b5ea131bfe11eeeb4b4c193f64a@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5510f0125ba409fc1cabd098ab8b457741e5fa314cbd0e61e4339422@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r55d807f31e64a080c54455897c20b1667ec792e5915132c7b7750533@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r56805265475919252ba7fc10123f15b91097f3009bae86476624ca25@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r643ba53f002ae59068f9352fe1d82e1b6f375387ffb776f13efe8fda@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r666f29a7d0e1f98fa1425ca01efcfa86e6e3856e01d300828aa7c6ea@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r6c91e52b3cc9f4e64afe0f34f20507143fd1f756d12681a56a9b38da@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r6d54c2da792c74cc14b9b7665ea89e144c9e238ed478d37fd56292e6@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r72a3588d62b2de1361dc9648f5d355385735e47f7ba49d089b0e680d@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r7ce3de03facf7e7f3e24fc25d26d555818519dafdb20f29398a3414b@%3Cdev.phoenix.apache.org%3E","https://lists.apache.org/thread.html/r8464b6ec951aace8c807bac9ea526d4f9e3116aa16d38be06f7c6524@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r8b57c57cffa01e418868a3c7535b987635ff1fb5ab534203bfa2d64a@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r900e020760c89f082df1c6e0d46320eba721e4e47bb9eb521e68cd95@%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/raebd2019b3da8c2f90f31e8b203b45353f78770ca93bfe5376f5532e@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb0e033d5ec8233360203431ad96580cf2ec56f47d9a425d894e279c2@%3Cpr.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rb34d8d3269ad47a1400f5a1a2d8310e13a80b6576ebd7f512144198d@%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb5c33d0069c927fae16084f0605895b98d231d7c48527bcb822ac48c@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rb7b28ac741e32dd5edb2c22485d635275bead7290b056ee56baf8ce0@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/rbaa1f513d903c89a08267c91d86811fa5bcc82e0596b6142c5cea7ea@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rc3211c71f7e0973a1825d1988a3921288c06cd9d793eae97ecd34948@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rcb2a7037366c58bac6aec6ce3df843a11ef97ae4eb049f05f410eaa5@%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rcb4b61dbe2ed1c7a88781a9aff5a9e7342cc7ed026aec0418ee67596@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rce5c93bba6e815fb62ad38e28ca1943b3019af1eddeb06507ad4e11a@%3Ccommits.atlas.apache.org%3E","https://lists.apache.org/thread.html/rd582c64f66c354240290072f340505f5d026ca944ec417226bb0272e@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/re791a854001ec1f79cd4f47328b270e7a1d9d7056debb8f16d962722@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/re851bbfbedd47c690b6e01942acb98ee08bd00df1a94910b905bc8cd@%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/reb1751562ee5146d3aca654a2df76a2c13d8036645ce69946f9c219e@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/recfe569f4f260328b0036f1c82b2956e864d519ab941a5e75d0d832d@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rf95bebee6dfcc55067cebe8482bd31e6f481d9f74ba8e03f860c3ec7@%3Ccommits.cassandra.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CKN7VGIKTYBCAKYBRG55QHXAY5UDZ7HA/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PTVJC54XGX26UJVVYCXZ7D25X3R5T2G6/","https://mvnrepository.com/artifact/org.yaml/snakeyaml/1.25/usages","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r16ae4e529401b75a1f5aa462b272b31bf2a108236f882f06fddc14bc@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r182e9cf6f3fb22b9be0cac4ff0685199741d2ab6e9a4e27a3693c224@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r465d2553a31265b042cf5457ef649b71e0722ab89b6ea94a5d59529b@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rdd34c0479587e32a656d976649409487d51ca0d296b3e26b6b89c3f5@%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rfe0aab6c3bebbd9cbfdedb65ff3fdf420714bcb8acdfd346077e1263@%3Ccommon-commits.hadoop.apache.org%3E","https://bitbucket.org/snakeyaml/snakeyaml/issues/377","https://bitbucket.org/snakeyaml/snakeyaml/wiki/Changes","https://security.gentoo.org/glsa/202305-28"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rvwf-54qp-4r6v","description":"SnakeYAML Entity Expansion during load operation"},"relatedVulnerabilities":[{"id":"CVE-2017-18640","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18640","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-18640","date":"2026-10-08","epss":0.26723,"percentile":0.97984}],"urls":["https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-preventing-billion","https://bitbucket.org/asomov/snakeyaml/wiki/Billion%20laughs%20attack","https://bitbucket.org/snakeyaml/snakeyaml/issues/377","https://bitbucket.org/snakeyaml/snakeyaml/wiki/Changes","https://lists.apache.org/thread.html/r1058e7646988394de6a3fd0857ea9b1ee0de14d7bb28fee5ff782457%40%3Ccommits.atlas.apache.org%3E","https://lists.apache.org/thread.html/r154090b871cf96d985b90864442d84eb027c72c94bc3f0a5727ba2d1%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r16ae4e529401b75a1f5aa462b272b31bf2a108236f882f06fddc14bc%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r1703a402f30c8a2ee409f8c6f393e95a63f8c952cc9ee5bf9dd586dc%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r182e9cf6f3fb22b9be0cac4ff0685199741d2ab6e9a4e27a3693c224%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r191ceadb1b883357384981848dfa5235cb02a90070c553afbaf9b3d9%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r1aab47b48a757c70e40fc0bcb1fcf1a3951afa6a17aee7cd66cf79f8%40%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r1dfac8b6a7097bcb4979402bbb6e2f8c36d0d9001e3018717eb22b7e%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r1ffce2ed3017e9964f03ad2c539d69e49144fc8e9bf772d641612f98%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r20350031c60a77b45e0eded33e9b3e9cb0cbfc5e24e1c63bf264df12%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r22ac2aa053b7d9c6b75a49db78125c9316499668d0f4a044f3402e2f%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r28c9009a48d52cf448f8b02cd823da0f8601d2dff4d66f387a35f1e0%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r2a5b84fdf59042dc398497e914b5bb1aed77328320b1438144ae1953%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r2b05744c0c2867daa5d1a96832965b7d6220328b0ead06c22a6e7854%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r2db207a2431a5e9e95e899858ab1f5eabd9bcc790a6ca7193ae07e94%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r436988d2cfe8a770ae361c82b181c5b2bf48a249bad84d8a55a3b46e%40%3Cdev.phoenix.apache.org%3E","https://lists.apache.org/thread.html/r465d2553a31265b042cf5457ef649b71e0722ab89b6ea94a5d59529b%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r4c682fb8cf69dd14162439656a6ebdf42ea6ad0e4edba95907ea3f14%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r4d7f37da1bc2df90a5a0f56eb7629b5ea131bfe11eeeb4b4c193f64a%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5510f0125ba409fc1cabd098ab8b457741e5fa314cbd0e61e4339422%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r55d807f31e64a080c54455897c20b1667ec792e5915132c7b7750533%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r56805265475919252ba7fc10123f15b91097f3009bae86476624ca25%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r643ba53f002ae59068f9352fe1d82e1b6f375387ffb776f13efe8fda%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r666f29a7d0e1f98fa1425ca01efcfa86e6e3856e01d300828aa7c6ea%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r6c91e52b3cc9f4e64afe0f34f20507143fd1f756d12681a56a9b38da%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r6d54c2da792c74cc14b9b7665ea89e144c9e238ed478d37fd56292e6%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/r72a3588d62b2de1361dc9648f5d355385735e47f7ba49d089b0e680d%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r7ce3de03facf7e7f3e24fc25d26d555818519dafdb20f29398a3414b%40%3Cdev.phoenix.apache.org%3E","https://lists.apache.org/thread.html/r8464b6ec951aace8c807bac9ea526d4f9e3116aa16d38be06f7c6524%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r8b57c57cffa01e418868a3c7535b987635ff1fb5ab534203bfa2d64a%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r900e020760c89f082df1c6e0d46320eba721e4e47bb9eb521e68cd95%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/raebd2019b3da8c2f90f31e8b203b45353f78770ca93bfe5376f5532e%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb0e033d5ec8233360203431ad96580cf2ec56f47d9a425d894e279c2%40%3Cpr.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rb34d8d3269ad47a1400f5a1a2d8310e13a80b6576ebd7f512144198d%40%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb5c33d0069c927fae16084f0605895b98d231d7c48527bcb822ac48c%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rb7b28ac741e32dd5edb2c22485d635275bead7290b056ee56baf8ce0%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/rbaa1f513d903c89a08267c91d86811fa5bcc82e0596b6142c5cea7ea%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rc3211c71f7e0973a1825d1988a3921288c06cd9d793eae97ecd34948%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rcb2a7037366c58bac6aec6ce3df843a11ef97ae4eb049f05f410eaa5%40%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rcb4b61dbe2ed1c7a88781a9aff5a9e7342cc7ed026aec0418ee67596%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rce5c93bba6e815fb62ad38e28ca1943b3019af1eddeb06507ad4e11a%40%3Ccommits.atlas.apache.org%3E","https://lists.apache.org/thread.html/rd582c64f66c354240290072f340505f5d026ca944ec417226bb0272e%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rdd34c0479587e32a656d976649409487d51ca0d296b3e26b6b89c3f5%40%3Ccommon-commits.hadoop.apache.org%3E","https://lists.apache.org/thread.html/re791a854001ec1f79cd4f47328b270e7a1d9d7056debb8f16d962722%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/re851bbfbedd47c690b6e01942acb98ee08bd00df1a94910b905bc8cd%40%3Cdev.atlas.apache.org%3E","https://lists.apache.org/thread.html/reb1751562ee5146d3aca654a2df76a2c13d8036645ce69946f9c219e%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/recfe569f4f260328b0036f1c82b2956e864d519ab941a5e75d0d832d%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rf95bebee6dfcc55067cebe8482bd31e6f481d9f74ba8e03f860c3ec7%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rfe0aab6c3bebbd9cbfdedb65ff3fdf420714bcb8acdfd346077e1263%40%3Ccommon-commits.hadoop.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKN7VGIKTYBCAKYBRG55QHXAY5UDZ7HA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTVJC54XGX26UJVVYCXZ7D25X3R5T2G6/","https://mvnrepository.com/artifact/org.yaml/snakeyaml/1.25/usages","https://security.gentoo.org/glsa/202305-28","https://www.oracle.com/security-alerts/cpuApr2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18640","description":"The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.35"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-53hp-jpwq-2jgq","versionConstraint":">=9.0.0.M1,<9.0.35 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-53hp-jpwq-2jgq","fix":{"state":"fixed","versions":["9.0.35"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"9.0.35"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-11996","date":"2026-10-08","epss":0.26699,"percentile":0.97981}],"risk":20.02425,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11996","https://lists.apache.org/thread.html/r2529016c311ce9485e6f173446d469600fdfbb94dccadfcd9dfdac79@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3ea96d8f36dd404acce83df8aeb22a9e807d6c13ca9c5dec72f872cd@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r5541ef6b6b68b49f76fc4c45695940116da2bcbe0312ef204a00a2e0%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r5a4f80a6acc6607d61dae424b643b594c6188dd4e1eff04705c10db2@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r6c29801370a36c1a5159679269777ad0c73276d3015b8bbefea66e5c@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r74f5a8204efe574cbfcd95b2a16236fe95beb45c4d9fee3dc789dca9@%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r8f3d416c193bc9384a8a7dd368623d441f5fcaff1057115008100561@%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r93ca628ef3a4530dfe5ac49fddc795f0920a4b2a408b57a30926a42b@%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r9ad911fe49450ed9405827af0e7a74104041081ff91864b1f2546bbd@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb4ee49ecc4c59620ffd5e66e84a17e526c2c3cfa95d0cd682d90d338@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb820f1a2a02bf07414be12c653c2ab5321fd87b9bf6c5e635c53ff4b@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rc80b96b4b96618b2b7461cb90664a428cfd6605eea9f74e51b792542@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rea65d6ef2e45dd1c45faae83922042732866c7b88fa109b76c83db52@%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/ref0339792ac6dac1dba83c071a727ad72380899bde60f6aaad4031b9@%3Cnotifications.ofbiz.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html","https://www.debian.org/security/2020/dsa-4727","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00072.html","https://github.com/apache/tomcat/commit/9434a44d3449d620b1be70206819f8275b4a7509","https://github.com/apache/tomcat/commit/9a0231683a77e2957cea0fdee88b193b30b0c976","https://usn.ubuntu.com/4596-1","https://security.netapp.com/advisory/ntap-20200709-0002","https://tomcat.apache.org/security-9.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-10.html","https://github.com/apache/tomcat/commit/c8acd2ab7371e39aeca7c306f3b5380f00afe552"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-53hp-jpwq-2jgq","description":"Uncontrolled Resource Consumption in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2020-11996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-11996","date":"2026-10-08","epss":0.26699,"percentile":0.97981}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00072.html","https://lists.apache.org/thread.html/r2529016c311ce9485e6f173446d469600fdfbb94dccadfcd9dfdac79%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3ea96d8f36dd404acce83df8aeb22a9e807d6c13ca9c5dec72f872cd%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r5541ef6b6b68b49f76fc4c45695940116da2bcbe0312ef204a00a2e0%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r5a4f80a6acc6607d61dae424b643b594c6188dd4e1eff04705c10db2%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r6c29801370a36c1a5159679269777ad0c73276d3015b8bbefea66e5c%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r74f5a8204efe574cbfcd95b2a16236fe95beb45c4d9fee3dc789dca9%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r8f3d416c193bc9384a8a7dd368623d441f5fcaff1057115008100561%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r93ca628ef3a4530dfe5ac49fddc795f0920a4b2a408b57a30926a42b%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r9ad911fe49450ed9405827af0e7a74104041081ff91864b1f2546bbd%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb4ee49ecc4c59620ffd5e66e84a17e526c2c3cfa95d0cd682d90d338%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb820f1a2a02bf07414be12c653c2ab5321fd87b9bf6c5e635c53ff4b%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rc80b96b4b96618b2b7461cb90664a428cfd6605eea9f74e51b792542%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rea65d6ef2e45dd1c45faae83922042732866c7b88fa109b76c83db52%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/ref0339792ac6dac1dba83c071a727ad72380899bde60f6aaad4031b9%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html","https://security.netapp.com/advisory/ntap-20200709-0002/","https://usn.ubuntu.com/4596-1/","https://www.debian.org/security/2020/dsa-4727","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11996","description":"A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-2398","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2398","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2398","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-2398","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"risk":18.0405,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2398"},"relatedVulnerabilities":[{"id":"CVE-2024-2398","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2398","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-2398","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"urls":["http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://www.openwall.com/lists/oss-security/2024/03/27/3","https://curl.se/docs/CVE-2024-2398.html","https://curl.se/docs/CVE-2024-2398.json","https://hackerone.com/reports/2402845","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/","https://security.netapp.com/advisory/ntap-20240503-0009/","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2398","description":"When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.  Further, this error condition fails silently and is therefore not easily detected by an application."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2398","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2398","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2398","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-2398","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"risk":18.0405,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2398"},"relatedVulnerabilities":[{"id":"CVE-2024-2398","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2398","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-2398","date":"2026-10-08","epss":0.36081,"percentile":0.98442}],"urls":["http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://www.openwall.com/lists/oss-security/2024/03/27/3","https://curl.se/docs/CVE-2024-2398.html","https://curl.se/docs/CVE-2024-2398.json","https://hackerone.com/reports/2402845","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/","https://security.netapp.com/advisory/ntap-20240503-0009/","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2398","description":"When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.  Further, this error condition fails silently and is therefore not easily detected by an application."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p43x-xfjf-5jhr","versionConstraint":">=2.9.0,<2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p43x-xfjf-5jhr","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9548","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9548","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9548","date":"2026-10-08","epss":0.18921,"percentile":0.97232}],"risk":17.78574,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-9548","https://github.com/FasterXML/jackson-databind/issues/2634","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/9f4e97019fb0dd836533d0b6198c88787e235ae2","https://github.com/FasterXML/jackson-databind/commit/1e64db6a2fad331f96c7363fda3bc5f3dffa25bb","https://security.netapp.com/advisory/ntap-20200904-0006"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p43x-xfjf-5jhr","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-9548","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9548","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9548","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9548","date":"2026-10-08","epss":0.18921,"percentile":0.97232}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2634","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-9548","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q93h-jc49-78gg","versionConstraint":">=2.9.0,<2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q93h-jc49-78gg","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9547","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9547","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9547","date":"2026-10-08","epss":0.18383,"percentile":0.97165}],"risk":17.28002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-9547","https://github.com/FasterXML/jackson-databind/issues/2634","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r742ef70d126548dcf7de5be5779355c9d76a9aec71d7a9ef02c6398a@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra3e90712f2d59f8cef03fa796f5adf163d32b81fe7b95385f21790e6@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd0e958d6d5c5ee16efed73314cd0e445c8dbb4bdcc80fc9d1d6c11fc@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/redbe4f1e21bf080f637cf9fbec47729750a2f443a919765360337428@%3Cnotifications.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/r4accb2e0de9679174efd3d113a059bab71ff3ec53e882790d21c1cc1@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc0d5d0f72da1ed6fc5e438b1ddb3fa090c73006b55f873cf845375ab@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/9f4e97019fb0dd836533d0b6198c88787e235ae2"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q93h-jc49-78gg","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-9547","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9547","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9547","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9547","date":"2026-10-08","epss":0.18383,"percentile":0.97165}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2634","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r4accb2e0de9679174efd3d113a059bab71ff3ec53e882790d21c1cc1%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r742ef70d126548dcf7de5be5779355c9d76a9aec71d7a9ef02c6398a%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra3e90712f2d59f8cef03fa796f5adf163d32b81fe7b95385f21790e6%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc0d5d0f72da1ed6fc5e438b1ddb3fa090c73006b55f873cf845375ab%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd0e958d6d5c5ee16efed73314cd0e445c8dbb4bdcc80fc9d1d6c11fc%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/redbe4f1e21bf080f637cf9fbec47729750a2f443a919765360337428%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-9547","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap)."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.19"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-32206","versionConstraint":"< 7.58.0-2ubuntu3.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32206","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.19"],"available":[{"date":"2022-06-27","kind":"advisory","version":"7.58.0-2ubuntu3.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32206","date":"2026-10-08","epss":0.33097,"percentile":0.98328}],"risk":16.5485,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32206"},"relatedVulnerabilities":[{"id":"CVE-2022-32206","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32206","date":"2026-10-08","epss":0.33097,"percentile":0.98328}],"urls":["http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","http://www.openwall.com/lists/oss-security/2023/02/15/3","https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf","https://hackerone.com/reports/1570651","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220915-0003/","https://support.apple.com/kb/HT213488","https://www.debian.org/security/2022/dsa-5197"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32206","description":"curl < 7.84.0 supports \"chained\" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \"links\" in this \"decompression chain\" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \"malloc bomb\", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-32206","versionConstraint":"< 7.58.0-2ubuntu3.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32206","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.19"],"available":[{"date":"2022-06-27","kind":"advisory","version":"7.58.0-2ubuntu3.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32206","date":"2026-10-08","epss":0.33097,"percentile":0.98328}],"risk":16.5485,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32206"},"relatedVulnerabilities":[{"id":"CVE-2022-32206","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32206","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32206","date":"2026-10-08","epss":0.33097,"percentile":0.98328}],"urls":["http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","http://www.openwall.com/lists/oss-security/2023/02/15/3","https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf","https://hackerone.com/reports/1570651","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220915-0003/","https://support.apple.com/kb/HT213488","https://www.debian.org/security/2022/dsa-5197"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32206","description":"curl < 7.84.0 supports \"chained\" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \"links\" in this \"decompression chain\" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \"malloc bomb\", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5ww9-j83m-q7qx","versionConstraint":">=2.9.0,<2.9.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5ww9-j83m-q7qx","fix":{"state":"fixed","versions":["2.9.9"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12086","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12086","date":"2026-10-08","epss":0.21949,"percentile":0.97604}],"risk":16.46175,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-12086","https://github.com/FasterXML/jackson-databind/issues/2326","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.9","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/88cd25375805950ae7337e669b0cb0eeda98b9604c1b8d806dccbad2@%3Creviews.spark.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/05/msg00030.html","https://seclists.org/bugtraq/2019/May/68","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679@%3Ccommits.nifi.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://web.archive.org/web/20200227030031/http://www.securityfocus.com/bid/109227","https://github.com/FasterXML/jackson-databind/commit/efc3c0d02f4743dbaa6d1b9c466772a2f13d966b","https://github.com/FasterXML/jackson-databind/commit/dda513bd7251b4f32b7b60b1c13740e3b5a43024","https://github.com/FasterXML/jackson-databind/commit/d30f036208ab1c60bd5ce429cb4f7f1a3e5682e8","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC","https://security.netapp.com/advisory/ntap-20190530-0003","https://web.archive.org/web/20200808181049/http://russiansecurity.expert/2016/04/20/mysql-connect-file-read"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5ww9-j83m-q7qx","description":"Information exposure in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-12086","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12086","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12086","date":"2026-10-08","epss":0.21949,"percentile":0.97604}],"urls":["http://russiansecurity.expert/2016/04/20/mysql-connect-file-read/","http://www.securityfocus.com/bid/109227","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://github.com/FasterXML/jackson-databind/issues/2326","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.9","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/88cd25375805950ae7337e669b0cb0eeda98b9604c1b8d806dccbad2%40%3Creviews.spark.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679%40%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/05/msg00030.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12086","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2511","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2511","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2511","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-2511","date":"2026-10-08","epss":0.52421,"percentile":0.98938}],"risk":15.726299999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2511"},"relatedVulnerabilities":[{"id":"CVE-2024-2511","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2511","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-2511","date":"2026-10-08","epss":0.52421,"percentile":0.98938}],"urls":["https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640","https://www.openssl.org/news/secadv/20240408.txt","http://www.openwall.com/lists/oss-security/2024/04/08/5","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240503-0013/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-354112.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2511","description":"Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-2511","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-2511","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2511","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-2511","date":"2026-10-08","epss":0.52421,"percentile":0.98938}],"risk":15.726299999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2511"},"relatedVulnerabilities":[{"id":"CVE-2024-2511","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2511","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-2511","date":"2026-10-08","epss":0.52421,"percentile":0.98938}],"urls":["https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640","https://www.openssl.org/news/secadv/20240408.txt","http://www.openwall.com/lists/oss-security/2024/04/08/5","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240503-0013/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-354112.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2511","description":"Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-23840","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23840","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.8"],"available":[{"date":"2021-02-18","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23840","date":"2026-10-08","epss":0.50732,"percentile":0.98897}],"risk":15.2196,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23840"},"relatedVulnerabilities":[{"id":"CVE-2021-23840","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23840","date":"2026-10-08","epss":0.50732,"percentile":0.98897}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=6a51b9e1d0cf0bf8515f7201b68fb0a3482b3dc1","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9b1129239f3ebb1d1c98ce9ed41d5c9476c47cb2","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846","https://kc.mcafee.com/corporate/index?page=content&id=SB10366","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210219-0009/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20210216.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-03","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23840","description":"Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-23840","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23840","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.8"],"available":[{"date":"2021-02-18","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23840","date":"2026-10-08","epss":0.50732,"percentile":0.98897}],"risk":15.2196,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23840"},"relatedVulnerabilities":[{"id":"CVE-2021-23840","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23840","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23840","date":"2026-10-08","epss":0.50732,"percentile":0.98897}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=6a51b9e1d0cf0bf8515f7201b68fb0a3482b3dc1","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9b1129239f3ebb1d1c98ce9ed41d5c9476c47cb2","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846","https://kc.mcafee.com/corporate/index?page=content&id=SB10366","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210219-0009/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20210216.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-03","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23840","description":"Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x)."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.86"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7w75-32cg-r6g2","versionConstraint":">=9.0.0-M1,<=9.0.85 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7w75-32cg-r6g2","fix":{"state":"fixed","versions":["9.0.86"],"available":[{"date":"2024-03-16","kind":"first-observed","version":"9.0.86"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-24549","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-24549","date":"2026-10-08","epss":0.23072,"percentile":0.97711}],"risk":13.90088,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-24549","https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg","https://github.com/apache/tomcat/commit/0cac540a882220231ba7a82330483cbd5f6b1f96","https://github.com/apache/tomcat/commit/810f49d5ff6d64b704af85d5b8d0aab9ec3c83f5","https://github.com/apache/tomcat/commit/8e03be9f2698f2da9027d40b9e9c0c9429b74dc0","https://github.com/apache/tomcat/commit/d07c82194edb69d99b438828fe2cbfadbb207843","https://security.netapp.com/advisory/ntap-20240402-0002","https://lists.debian.org/debian-lts-announce/2024/04/msg00001.html","http://www.openwall.com/lists/oss-security/2024/03/13/3","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/736G4GPZWS2DSQO5WKXO3G6OMZKFEK55","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UWIS5MMGYDZBLJYT674ZI5AWFHDZ46B"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7w75-32cg-r6g2","description":"Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests"},"relatedVulnerabilities":[{"id":"CVE-2024-24549","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-24549","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-24549","date":"2026-10-08","epss":0.23072,"percentile":0.97711}],"urls":["https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg","http://www.openwall.com/lists/oss-security/2024/03/13/3","https://lists.debian.org/debian-lts-announce/2024/04/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UWIS5MMGYDZBLJYT674ZI5AWFHDZ46B/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/736G4GPZWS2DSQO5WKXO3G6OMZKFEK55/","https://security.netapp.com/advisory/ntap-20240402-0002/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24549","description":"Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.43"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j39c-c8hj-x4j3","versionConstraint":">=9.0.0-M1,<9.0.43 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j39c-c8hj-x4j3","fix":{"state":"fixed","versions":["9.0.43"],"available":[{"date":"2021-06-17","kind":"first-observed","version":"9.0.43"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-25122","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-25122","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-25122","date":"2026-10-08","epss":0.18114,"percentile":0.97132}],"risk":13.5855,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-25122","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rcd90bf36b1877e1310b87ecd14ed7bbb15da52b297efd9f0e7253a3b@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd0463f9a5cbc02a485404c4b990f0da452e5ac5c237808edba11c947@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9@%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","http://www.openwall.com/lists/oss-security/2021/03/01/1","https://www.debian.org/security/2021/dsa-4891","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://security.gentoo.org/glsa/202208-34","https://security.netapp.com/advisory/ntap-20210409-0002","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd0463f9a5cbc02a485404c4b990f0da452e5ac5c237808edba11c947%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rcd90bf36b1877e1310b87ecd14ed7bbb15da52b297efd9f0e7253a3b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.apache.org%3E"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j39c-c8hj-x4j3","description":"Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2021-25122","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-25122","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-25122","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-25122","date":"2026-10-08","epss":0.18114,"percentile":0.97132}],"urls":["http://www.openwall.com/lists/oss-security/2021/03/01/1","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7b95bc248603360501f18c8eb03bb6001ec0ee3296205b34b07105b7%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rcd90bf36b1877e1310b87ecd14ed7bbb15da52b297efd9f0e7253a3b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd0463f9a5cbc02a485404c4b990f0da452e5ac5c237808edba11c947%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","https://security.gentoo.org/glsa/202208-34","https://security.netapp.com/advisory/ntap-20210409-0002/","https://www.debian.org/security/2021/dsa-4891","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-25122","description":"When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-4559","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2007-4559","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"risk":13.547500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2007-4559"},"relatedVulnerabilities":[{"id":"CVE-2007-4559","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"urls":["http://mail.python.org/pipermail/python-dev/2007-August/074290.html","http://mail.python.org/pipermail/python-dev/2007-August/074292.html","http://secunia.com/advisories/26623","http://www.vupen.com/english/advisories/2007/3022","https://bugzilla.redhat.com/show_bug.cgi?id=263261","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/","https://security.gentoo.org/glsa/202309-06","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-4559","description":"Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-4559","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2007-4559","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"risk":13.547500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2007-4559"},"relatedVulnerabilities":[{"id":"CVE-2007-4559","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"urls":["http://mail.python.org/pipermail/python-dev/2007-August/074290.html","http://mail.python.org/pipermail/python-dev/2007-August/074292.html","http://secunia.com/advisories/26623","http://www.vupen.com/english/advisories/2007/3022","https://bugzilla.redhat.com/show_bug.cgi?id=263261","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/","https://security.gentoo.org/glsa/202309-06","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-4559","description":"Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2007-4559","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2007-4559","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"risk":13.547500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2007-4559"},"relatedVulnerabilities":[{"id":"CVE-2007-4559","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"urls":["http://mail.python.org/pipermail/python-dev/2007-August/074290.html","http://mail.python.org/pipermail/python-dev/2007-August/074292.html","http://secunia.com/advisories/26623","http://www.vupen.com/english/advisories/2007/3022","https://bugzilla.redhat.com/show_bug.cgi?id=263261","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/","https://security.gentoo.org/glsa/202309-06","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-4559","description":"Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-4559","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2007-4559","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"risk":13.547500000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2007-4559"},"relatedVulnerabilities":[{"id":"CVE-2007-4559","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2007-4559","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2007-4559","date":"2026-10-08","epss":0.27095,"percentile":0.98006}],"urls":["http://mail.python.org/pipermail/python-dev/2007-August/074290.html","http://mail.python.org/pipermail/python-dev/2007-August/074292.html","http://secunia.com/advisories/26623","http://www.vupen.com/english/advisories/2007/3022","https://bugzilla.redhat.com/show_bug.cgi?id=263261","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/","https://security.gentoo.org/glsa/202309-06","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-4559","description":"Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9gph-22xh-8x98","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9gph-22xh-8x98","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36179","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36179","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36179","date":"2026-10-08","epss":0.17065,"percentile":0.97009}],"risk":13.3107,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36179","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/rc255f41d9a61d3dc79a51fb5c713de4ae10e71e3673feeb0b180b436@%3Cissues.spark.apache.org%3E","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9gph-22xh-8x98","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36179","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36179","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36179","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36179","date":"2026-10-08","epss":0.17065,"percentile":0.97009}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/3004","https://lists.apache.org/thread.html/rc255f41d9a61d3dc79a51fb5c713de4ae10e71e3673feeb0b180b436%40%3Cissues.spark.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36179","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS."}]},{"artifact":{"id":"13e5904e4425c8fe","cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.35-2ubuntu2.7:*:*:*:*:*:*:*"],"name":"libnss3","purl":"pkg:deb/ubuntu/libnss3@2%3A3.35-2ubuntu2.7?arch=amd64&distro=ubuntu-18.04&upstream=nss","type":"deb","version":"2:3.35-2ubuntu2.7","language":"","licenses":["HPND","HPND-sell-variant","MIT","MPL-2.0","Zlib","blessing"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nss"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.35-2ubuntu2.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-43527","versionConstraint":"< 2:3.35-2ubuntu2.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nss","version":"2:3.35-2ubuntu2.7"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-43527","fix":{"state":"fixed","versions":["2:3.35-2ubuntu2.13"],"available":[{"date":"2021-12-01","kind":"advisory","version":"2:3.35-2ubuntu2.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-43527","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-43527","date":"2026-10-08","epss":0.17563,"percentile":0.97071}],"risk":13.172250000000002,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-43527"},"relatedVulnerabilities":[{"id":"CVE-2021-43527","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-43527","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-43527","date":"2026-10-08","epss":0.17563,"percentile":0.97071}],"urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=1737470","https://cert-portal.siemens.com/productcert/pdf/ssa-594438.pdf","https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_68_1_RTM/","https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_73_RTM/","https://security.gentoo.org/glsa/202212-05","https://security.netapp.com/advisory/ntap-20211229-0002/","https://www.mozilla.org/security/advisories/mfsa2021-51/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.starwindsoftware.com/security/sw-20220802-0001/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-43527","description":"NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \\#7, or PKCS \\#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-288c-cq4h-88gq","versionConstraint":">=2.7.0.0,<=2.9.10.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-288c-cq4h-88gq","fix":{"state":"fixed","versions":["2.9.10.7"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25649","cwe":"CWE-611","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-25649","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25649","date":"2026-10-08","epss":0.1726,"percentile":0.97035}],"risk":12.945,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-25649","https://github.com/FasterXML/jackson-databind/issues/2589","https://bugzilla.redhat.com/show_bug.cgi?id=1887664","https://lists.apache.org/thread.html/r04529cedaca40c2ff90af4880493f9c88a8ebf4d1d6c861d23108a5a@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r0b8dc3acd4503e4ecb6fbd6ea7d95f59941168d8452ac0ab1d1d96bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r1b7ed0c4b6c4301d4dfd6fdbc5581b0a789d3240cab55d766f33c6c6@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r2882fc1f3032cd7be66e28787f04ec6f1874ac68d47e310e30ff7eb1@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r2b6ddb3a4f4cd11d8f6305011e1b7438ba813511f2e3ab3180c7ffda@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r31f4ee7d561d56a0c2c2c6eb1d6ce3e05917ff9654fdbfec05dc2b83@%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r3e6ae311842de4e64c5d560a475b7f9cc7e0a9a8649363c6cf7537eb@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r45e7350dfc92bb192f3f88e9971c11ab2be0953cc375be3dda5170bd@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r5f8a1608d758936bd6bbc5eed980777437b611537bf6fff40663fc71@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r63c87aab97155f3f3cbe11d030c4a184ea0de440ee714977db02e956@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r68d029ee74ab0f3b0569d0c05f5688cb45dd3abe96a6534735252805@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r6e3d4f7991542119a4ca6330271d7fbf7b9fb3abab24ada82ddf1ee4@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r78d53a0a269c18394daf5940105dc8c7f9a2399503c2e78be20abe7e@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r86c78bf7656fdb2dab69cbf17f3d7492300f771025f1a3a65d5e5ce5@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r900d4408c4189b376d1ec580ea7740ea6f8710dc2f0b7e9c9eeb5ae0@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r90d1e97b0a743cf697d89a792a9b669909cc5a1692d1e0083a22e66c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r91722ecfba688b0c565675f8bf380269fde8ec62b54d6161db544c22@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r94c7e86e546120f157264ba5ba61fd29b3a8d530ed325a9b4fa334d7@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r95a297eb5fd1f2d3a2281f15340e2413f952e9d5503296c3adc7201a@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r98bfe3b90ea9408f12c4b447edcb5638703d80bc782430aa0c210a54@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra1157e57a01d25e36b0dc17959ace758fc21ba36746de29ba1d8b130@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/ra95faf968f3463acb3f31a6fbec31453fc5045325f99f396961886d3@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/raf13235de6df1d47a717199e1ecd700dff3236632f5c9a1488d9845b@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rb674520b9f6c808c1bf263b1369e14048ec3243615f35cfd24e33604@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc15e90bbef196a5c6c01659e015249d6c9a73581ca9afb8aeecf00d2@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rc88f2fa2b7bd6443921727aeee7704a1fb02433e722e2abf677e0d3d@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc959cdb57c4fe198316130ff4a5ecbf9d680e356032ff2e9f4f05d54@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rd317f15a675d114dbf5b488d27eeb2467b4424356b16116eb18a652d@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rd6f6bf848c2d47fa4a85c27d011d948778b8f7e58ba495968435a0b3@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdf9a34726482222c90d50ae1b9847881de67dde8cfde4999633d2cdc@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re16f81d3ad49a93dd2f0cba9f8fc88e5fb89f30bf9a2ad7b6f3e69c1@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/re96dc7a13e13e56190a5d80f9e5440a0d0c83aeec6467b562fbf2dca@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rf1809a1374041a969d77afab21fc38925de066bc97e86157d3ac3402@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r0881e23bd9034c8f51fdccdc8f4d085ba985dcd738f8520569ca5c3d@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r2eb66c182853c69ecfb52f63d3dec09495e9b65be829fd889a081ae1@%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/r5b130fe668503c4b7e2caf1b16f86b7f2070fd1b7ef8f26195a2ffbd@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd57c7582adc90e233f23f3727db3df9115b27a823b92374f11453f34@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r011d1430e8f40dff9550c3bc5d0f48b14c01ba8aecabd91d5e495386@%3Ccommits.turbine.apache.org%3E","https://lists.apache.org/thread.html/r2f5c5479f99398ef344b7ebd4d90bc3316236c45d0f3bc42090efcd7@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r407538adec3185dd35a05c9a26ae2f74425b15132470cf540f41d85b@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r605764e05e201db33b3e9c2e66ff620658f07ad74f296abe483f7042@%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r765283e145049df9b8998f14dcd444345555aae02b1610cfb3188bf8@%3Cnotifications.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r7cb5b4b3e4bd41a8042e5725b7285877a17bcbf07f4eb3f7b316af60@%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r6cbd599b80e787f02ff7a1391d9278a03f37d6a6f4f943f0f01a62fb@%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r73bef1bb601a9f093f915f8075eb49fcca51efade57b817afd5def07@%3Ccommits.iotdb.apache.org%3E","https://lists.apache.org/thread.html/ra409f798a1e5a6652b7097429b388650ccd65fd958cee0b6f69bba00@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rdca8711bb7aa5d47a44682606cd0ea3497e2e922f22b7ee83e81e6c1@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r8ae961c80930e2717c75025414ce48a432cea1137c02f648b1fb9524@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r6a4f3ef6edfed2e0884269d84798f766779bbbc1005f7884e0800d61@%3Cdev.knox.apache.org%3E","https://lists.apache.org/thread.html/rc82ff47853289e9cd17f5cfbb053c04cafc75ee32e3d7223963f83bb@%3Cdev.knox.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r8764bb835bcb8e311c882ff91dd3949c9824e905e880930be56f6ba3@%3Cuser.spark.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cusers.kafka.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r024b7bda9c43c5560d81238748775c5ecfe01b57280f90df1f773949@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r6a6df5647583541e3cb71c75141008802f7025cee1c430d4ed78f4cc@%3Cissues.hive.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3d932709abd0b5390efe67451653fc9efa9db677","https://github.com/FasterXML/jackson-databind/commit/612f971b78c60202e9cd75a299050c8f2d724a59","https://security.netapp.com/advisory/ntap-20210108-0007","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6X2UT4X6M7DLQYBOOHMXBWGYJ65RL2CT"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-288c-cq4h-88gq","description":"XML External Entity (XXE) Injection in Jackson Databind"},"relatedVulnerabilities":[{"id":"CVE-2020-25649","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25649","cwe":"CWE-611","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-25649","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25649","date":"2026-10-08","epss":0.1726,"percentile":0.97035}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1887664","https://github.com/FasterXML/jackson-databind/issues/2589","https://lists.apache.org/thread.html/r011d1430e8f40dff9550c3bc5d0f48b14c01ba8aecabd91d5e495386%40%3Ccommits.turbine.apache.org%3E","https://lists.apache.org/thread.html/r024b7bda9c43c5560d81238748775c5ecfe01b57280f90df1f773949%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r04529cedaca40c2ff90af4880493f9c88a8ebf4d1d6c861d23108a5a%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r0881e23bd9034c8f51fdccdc8f4d085ba985dcd738f8520569ca5c3d%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r0b8dc3acd4503e4ecb6fbd6ea7d95f59941168d8452ac0ab1d1d96bb%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r1b7ed0c4b6c4301d4dfd6fdbc5581b0a789d3240cab55d766f33c6c6%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r2882fc1f3032cd7be66e28787f04ec6f1874ac68d47e310e30ff7eb1%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r2b6ddb3a4f4cd11d8f6305011e1b7438ba813511f2e3ab3180c7ffda%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r2eb66c182853c69ecfb52f63d3dec09495e9b65be829fd889a081ae1%40%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/r2f5c5479f99398ef344b7ebd4d90bc3316236c45d0f3bc42090efcd7%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r31f4ee7d561d56a0c2c2c6eb1d6ce3e05917ff9654fdbfec05dc2b83%40%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r3e6ae311842de4e64c5d560a475b7f9cc7e0a9a8649363c6cf7537eb%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r407538adec3185dd35a05c9a26ae2f74425b15132470cf540f41d85b%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r45e7350dfc92bb192f3f88e9971c11ab2be0953cc375be3dda5170bd%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r5b130fe668503c4b7e2caf1b16f86b7f2070fd1b7ef8f26195a2ffbd%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r5f8a1608d758936bd6bbc5eed980777437b611537bf6fff40663fc71%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r605764e05e201db33b3e9c2e66ff620658f07ad74f296abe483f7042%40%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r63c87aab97155f3f3cbe11d030c4a184ea0de440ee714977db02e956%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r68d029ee74ab0f3b0569d0c05f5688cb45dd3abe96a6534735252805%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r6a4f3ef6edfed2e0884269d84798f766779bbbc1005f7884e0800d61%40%3Cdev.knox.apache.org%3E","https://lists.apache.org/thread.html/r6a6df5647583541e3cb71c75141008802f7025cee1c430d4ed78f4cc%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r6cbd599b80e787f02ff7a1391d9278a03f37d6a6f4f943f0f01a62fb%40%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r6e3d4f7991542119a4ca6330271d7fbf7b9fb3abab24ada82ddf1ee4%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r73bef1bb601a9f093f915f8075eb49fcca51efade57b817afd5def07%40%3Ccommits.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r765283e145049df9b8998f14dcd444345555aae02b1610cfb3188bf8%40%3Cnotifications.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r78d53a0a269c18394daf5940105dc8c7f9a2399503c2e78be20abe7e%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r7cb5b4b3e4bd41a8042e5725b7285877a17bcbf07f4eb3f7b316af60%40%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r86c78bf7656fdb2dab69cbf17f3d7492300f771025f1a3a65d5e5ce5%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8764bb835bcb8e311c882ff91dd3949c9824e905e880930be56f6ba3%40%3Cuser.spark.apache.org%3E","https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8ae961c80930e2717c75025414ce48a432cea1137c02f648b1fb9524%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r900d4408c4189b376d1ec580ea7740ea6f8710dc2f0b7e9c9eeb5ae0%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r90d1e97b0a743cf697d89a792a9b669909cc5a1692d1e0083a22e66c%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r91722ecfba688b0c565675f8bf380269fde8ec62b54d6161db544c22%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r94c7e86e546120f157264ba5ba61fd29b3a8d530ed325a9b4fa334d7%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r95a297eb5fd1f2d3a2281f15340e2413f952e9d5503296c3adc7201a%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r98bfe3b90ea9408f12c4b447edcb5638703d80bc782430aa0c210a54%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra1157e57a01d25e36b0dc17959ace758fc21ba36746de29ba1d8b130%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/ra409f798a1e5a6652b7097429b388650ccd65fd958cee0b6f69bba00%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/ra95faf968f3463acb3f31a6fbec31453fc5045325f99f396961886d3%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/raf13235de6df1d47a717199e1ecd700dff3236632f5c9a1488d9845b%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rb674520b9f6c808c1bf263b1369e14048ec3243615f35cfd24e33604%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rc15e90bbef196a5c6c01659e015249d6c9a73581ca9afb8aeecf00d2%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rc82ff47853289e9cd17f5cfbb053c04cafc75ee32e3d7223963f83bb%40%3Cdev.knox.apache.org%3E","https://lists.apache.org/thread.html/rc88f2fa2b7bd6443921727aeee7704a1fb02433e722e2abf677e0d3d%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc959cdb57c4fe198316130ff4a5ecbf9d680e356032ff2e9f4f05d54%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rd317f15a675d114dbf5b488d27eeb2467b4424356b16116eb18a652d%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rd57c7582adc90e233f23f3727db3df9115b27a823b92374f11453f34%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd6f6bf848c2d47fa4a85c27d011d948778b8f7e58ba495968435a0b3%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdca8711bb7aa5d47a44682606cd0ea3497e2e922f22b7ee83e81e6c1%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rdf9a34726482222c90d50ae1b9847881de67dde8cfde4999633d2cdc%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re16f81d3ad49a93dd2f0cba9f8fc88e5fb89f30bf9a2ad7b6f3e69c1%40%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/re96dc7a13e13e56190a5d80f9e5440a0d0c83aeec6467b562fbf2dca%40%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rf1809a1374041a969d77afab21fc38925de066bc97e86157d3ac3402%40%3Ccommits.karaf.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6X2UT4X6M7DLQYBOOHMXBWGYJ65RL2CT/","https://security.netapp.com/advisory/ntap-20210108-0007/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25649","description":"A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.40"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2rvv-w9r2-rg7m","versionConstraint":">=9.0.0,<9.0.40 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-2rvv-w9r2-rg7m","fix":{"state":"fixed","versions":["9.0.40"],"available":[{"date":"2021-05-14","kind":"first-observed","version":"9.0.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-24122","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-24122","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-24122","date":"2026-10-08","epss":0.22852,"percentile":0.9769}],"risk":12.454340000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-24122","https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7382e1e35b9bc7c8f320b90ad77e74c13172d08034e20c18000fe710@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r776c64337495bf28b7d5597268114a888e3fad6045c40a0da0c66d4d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r7e0bb9ea415724550e2b325e143b23e269579e54d66fcd7754bd0c20@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb32a73b7cb919d4f44a2596b6b951274c0004fc8b0e393d6829a45f9@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rca833c6d42b7b9ce1563488c0929f29fcc95947d86e5e740258c8937@%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","http://www.openwall.com/lists/oss-security/2021/01/14/1","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/apache/tomcat/commit/7f004ac4531c45f9a2a2d1470561fe135cf27bc2","https://github.com/apache/tomcat/commit/800b03140e640f8892f27021e681645e8e320177","https://github.com/apache/tomcat/commit/920dddbdb981f92e8d5872a4bb126a10af5ca8a9","https://github.com/apache/tomcat/commit/935fc5582dc25ae10bab6f9d5629ff8d996cb533","https://tomcat.apache.org/security-9.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-7.html","https://tomcat.apache.org/security-10.html","https://security.netapp.com/advisory/ntap-20210212-0008"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2rvv-w9r2-rg7m","description":"Information Disclosure in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2021-24122","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-24122","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-24122","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-24122","date":"2026-10-08","epss":0.22852,"percentile":0.9769}],"urls":["http://www.openwall.com/lists/oss-security/2021/01/14/1","https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r1595889b083e05986f42b944dc43060d6b083022260b6ea64d2cec52%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7382e1e35b9bc7c8f320b90ad77e74c13172d08034e20c18000fe710%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r776c64337495bf28b7d5597268114a888e3fad6045c40a0da0c66d4d%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r7e0bb9ea415724550e2b325e143b23e269579e54d66fcd7754bd0c20%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb32a73b7cb919d4f44a2596b6b951274c0004fc8b0e393d6829a45f9%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rca833c6d42b7b9ce1563488c0929f29fcc95947d86e5e740258c8937%40%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","https://security.netapp.com/advisory/ntap-20210212-0008/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-24122","description":"When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-23336","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23336","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"risk":12.2208,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23336"},"relatedVulnerabilities":[{"id":"CVE-2021-23336","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:P","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"urls":["http://www.openwall.com/lists/oss-security/2021/02/19/4","http://www.openwall.com/lists/oss-security/2021/05/01/2","https://github.com/python/cpython/pull/24297","https://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3E","https://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00030.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00015.html","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3EPYWWFDV22CJ5AOH5VCE72DOASZZ255/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YKKDLXL3UEZ3J426C2XTBS63AHE46SM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46N6A52EGSXHJYCZWVMBJJIH4NWIV2B5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZTM7KLHFCE3LWSEVO2NAFLUHMGYMCRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHQDU7NXA7EWAE4W7VO6MURVJIULEPPR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJXCMHLY7H3FIYLE4OKDYUILU2CCRUCZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LVNH6Z24IG3E67ZCQGGJ46FZB4XFLQNZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MNUN5SOMFL2BBKP6ZAICIIUPQKZDMGYO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJSCSN722JO2E2AGPWD4NTGVELVRPB4R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OAGSWNGZJ6HQ5ISA67SNMK3CJRKICET7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFTELUMWZE3KV3JB2H5EE6VFRZFRD5MV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W2LSKBEFI5SYEY5FM6ICZVZM5WRQUCS4/","https://security.gentoo.org/glsa/202104-04","https://security.netapp.com/advisory/ntap-20210326-0004/","https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/","https://snyk.io/vuln/SNYK-UPSTREAM-PYTHONCPYTHON-1074933","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23336","description":"The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-23336","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23336","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"risk":12.2208,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23336"},"relatedVulnerabilities":[{"id":"CVE-2021-23336","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:P","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"urls":["http://www.openwall.com/lists/oss-security/2021/02/19/4","http://www.openwall.com/lists/oss-security/2021/05/01/2","https://github.com/python/cpython/pull/24297","https://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3E","https://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00030.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00015.html","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3EPYWWFDV22CJ5AOH5VCE72DOASZZ255/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YKKDLXL3UEZ3J426C2XTBS63AHE46SM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46N6A52EGSXHJYCZWVMBJJIH4NWIV2B5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZTM7KLHFCE3LWSEVO2NAFLUHMGYMCRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHQDU7NXA7EWAE4W7VO6MURVJIULEPPR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJXCMHLY7H3FIYLE4OKDYUILU2CCRUCZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LVNH6Z24IG3E67ZCQGGJ46FZB4XFLQNZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MNUN5SOMFL2BBKP6ZAICIIUPQKZDMGYO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJSCSN722JO2E2AGPWD4NTGVELVRPB4R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OAGSWNGZJ6HQ5ISA67SNMK3CJRKICET7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFTELUMWZE3KV3JB2H5EE6VFRZFRD5MV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W2LSKBEFI5SYEY5FM6ICZVZM5WRQUCS4/","https://security.gentoo.org/glsa/202104-04","https://security.netapp.com/advisory/ntap-20210326-0004/","https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/","https://snyk.io/vuln/SNYK-UPSTREAM-PYTHONCPYTHON-1074933","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23336","description":"The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-23336","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23336","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"risk":12.2208,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23336"},"relatedVulnerabilities":[{"id":"CVE-2021-23336","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:P","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"urls":["http://www.openwall.com/lists/oss-security/2021/02/19/4","http://www.openwall.com/lists/oss-security/2021/05/01/2","https://github.com/python/cpython/pull/24297","https://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3E","https://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00030.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00015.html","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3EPYWWFDV22CJ5AOH5VCE72DOASZZ255/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YKKDLXL3UEZ3J426C2XTBS63AHE46SM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46N6A52EGSXHJYCZWVMBJJIH4NWIV2B5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZTM7KLHFCE3LWSEVO2NAFLUHMGYMCRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHQDU7NXA7EWAE4W7VO6MURVJIULEPPR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJXCMHLY7H3FIYLE4OKDYUILU2CCRUCZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LVNH6Z24IG3E67ZCQGGJ46FZB4XFLQNZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MNUN5SOMFL2BBKP6ZAICIIUPQKZDMGYO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJSCSN722JO2E2AGPWD4NTGVELVRPB4R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OAGSWNGZJ6HQ5ISA67SNMK3CJRKICET7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFTELUMWZE3KV3JB2H5EE6VFRZFRD5MV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W2LSKBEFI5SYEY5FM6ICZVZM5WRQUCS4/","https://security.gentoo.org/glsa/202104-04","https://security.netapp.com/advisory/ntap-20210326-0004/","https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/","https://snyk.io/vuln/SNYK-UPSTREAM-PYTHONCPYTHON-1074933","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23336","description":"The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-23336","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23336","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"risk":12.2208,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23336"},"relatedVulnerabilities":[{"id":"CVE-2021-23336","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:P","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-23336","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-23336","date":"2026-10-08","epss":0.40736,"percentile":0.98622}],"urls":["http://www.openwall.com/lists/oss-security/2021/02/19/4","http://www.openwall.com/lists/oss-security/2021/05/01/2","https://github.com/python/cpython/pull/24297","https://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3E","https://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00030.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00015.html","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3EPYWWFDV22CJ5AOH5VCE72DOASZZ255/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YKKDLXL3UEZ3J426C2XTBS63AHE46SM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46N6A52EGSXHJYCZWVMBJJIH4NWIV2B5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZTM7KLHFCE3LWSEVO2NAFLUHMGYMCRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHQDU7NXA7EWAE4W7VO6MURVJIULEPPR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJXCMHLY7H3FIYLE4OKDYUILU2CCRUCZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LVNH6Z24IG3E67ZCQGGJ46FZB4XFLQNZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MNUN5SOMFL2BBKP6ZAICIIUPQKZDMGYO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6VXJZSZ6N64AILJX4CTMACYGQGHHD5C/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJSCSN722JO2E2AGPWD4NTGVELVRPB4R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OAGSWNGZJ6HQ5ISA67SNMK3CJRKICET7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFTELUMWZE3KV3JB2H5EE6VFRZFRD5MV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W2LSKBEFI5SYEY5FM6ICZVZM5WRQUCS4/","https://security.gentoo.org/glsa/202104-04","https://security.netapp.com/advisory/ntap-20210326-0004/","https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/","https://snyk.io/vuln/SNYK-UPSTREAM-PYTHONCPYTHON-1074933","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23336","description":"The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3177","versionConstraint":"< 3.6.9-1~18.04ubuntu1.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3177","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.4"],"available":[{"date":"2021-02-25","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"risk":11.6465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3177"},"relatedVulnerabilities":[{"id":"CVE-2021-3177","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"urls":["https://bugs.python.org/issue42938","https://github.com/python/cpython/pull/24239","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/","https://news.ycombinator.com/item?id=26185005","https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20210226-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3177","description":"Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3177","versionConstraint":"< 3.6.9-1~18.04ubuntu1.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3177","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.4"],"available":[{"date":"2021-02-25","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"risk":11.6465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3177"},"relatedVulnerabilities":[{"id":"CVE-2021-3177","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"urls":["https://bugs.python.org/issue42938","https://github.com/python/cpython/pull/24239","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/","https://news.ycombinator.com/item?id=26185005","https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20210226-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3177","description":"Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3177","versionConstraint":"< 3.6.9-1~18.04ubuntu1.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3177","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.4"],"available":[{"date":"2021-02-25","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"risk":11.6465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3177"},"relatedVulnerabilities":[{"id":"CVE-2021-3177","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"urls":["https://bugs.python.org/issue42938","https://github.com/python/cpython/pull/24239","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/","https://news.ycombinator.com/item?id=26185005","https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20210226-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3177","description":"Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3177","versionConstraint":"< 3.6.9-1~18.04ubuntu1.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3177","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.4"],"available":[{"date":"2021-02-25","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"risk":11.6465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3177"},"relatedVulnerabilities":[{"id":"CVE-2021-3177","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3177","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-3177","date":"2026-10-08","epss":0.23293,"percentile":0.97729}],"urls":["https://bugs.python.org/issue42938","https://github.com/python/cpython/pull/24239","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html","https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/","https://news.ycombinator.com/item?id=26185005","https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20210226-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3177","description":"Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely."}]},{"artifact":{"id":"8e62788fd0d03826","cpes":["cpe:2.3:a:org.springframework.security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:security:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-security-core","purl":"pkg:maven/org.springframework.security/spring-security-core@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.security","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-core-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-security-core","archiveDigests":[{"value":"1c8f36e316a74c245073ce2a70bdf198a58424f6","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-core-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hh32-7344-cg2f","versionConstraint":"<5.4.11 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.security:spring-security-core","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hh32-7344-cg2f","fix":{"state":"fixed","versions":["5.4.11"],"available":[{"date":"2024-07-06","kind":"first-observed","version":"5.4.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22978","date":"2026-10-08","epss":0.12351,"percentile":0.96102}],"risk":11.60994,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22978","https://tanzu.vmware.com/security/cve-2022-22978","https://www.oracle.com/security-alerts/cpujul2022.html","https://spring.io/security/cve-2022-22978","https://security.netapp.com/advisory/ntap-20220707-0003","https://github.com/anchore/grype/issues/2158","https://github.com/spring-projects/spring-security/blob/main/web/src/main/java/org/springframework/security/web/util/matcher/RegexRequestMatcher.java"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hh32-7344-cg2f","description":"Authorization bypass in Spring Security"},"relatedVulnerabilities":[{"id":"CVE-2022-22978","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22978","date":"2026-10-08","epss":0.12351,"percentile":0.96102}],"urls":["https://spring.io/security/cve-2022-22978"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22978","description":"In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass."}]},{"artifact":{"id":"e268379bae5d9fad","cpes":["cpe:2.3:a:org.springframework.security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:security:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-security-web","purl":"pkg:maven/org.springframework.security/spring-security-web@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.security","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-web-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-security-web","archiveDigests":[{"value":"a9ff06ad3fd66cd08545e1a601c66d2256c86e0f","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-web-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hh32-7344-cg2f","versionConstraint":"<5.4.11 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.security:spring-security-web","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hh32-7344-cg2f","fix":{"state":"fixed","versions":["5.4.11"],"available":[{"date":"2024-10-05","kind":"first-observed","version":"5.4.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22978","date":"2026-10-08","epss":0.12351,"percentile":0.96102}],"risk":11.60994,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22978","https://tanzu.vmware.com/security/cve-2022-22978","https://www.oracle.com/security-alerts/cpujul2022.html","https://spring.io/security/cve-2022-22978","https://security.netapp.com/advisory/ntap-20220707-0003","https://github.com/anchore/grype/issues/2158","https://github.com/spring-projects/spring-security/blob/main/web/src/main/java/org/springframework/security/web/util/matcher/RegexRequestMatcher.java"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hh32-7344-cg2f","description":"Authorization bypass in Spring Security"},"relatedVulnerabilities":[{"id":"CVE-2022-22978","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22978","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22978","date":"2026-10-08","epss":0.12351,"percentile":0.96102}],"urls":["https://spring.io/security/cve-2022-22978"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22978","description":"In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass."}]},{"artifact":{"id":"7a6dcfb98884d7c9","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1ubuntu0.3?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1ubuntu0.3","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-35737","versionConstraint":"< 3.22.0-1ubuntu0.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-35737","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.7"],"available":[{"date":"2022-11-07","kind":"advisory","version":"3.22.0-1ubuntu0.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-35737","cwe":"CWE-129","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-35737","date":"2026-10-08","epss":0.22774,"percentile":0.97683}],"risk":11.387,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-35737"},"relatedVulnerabilities":[{"id":"CVE-2022-35737","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-35737","cwe":"CWE-129","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-35737","date":"2026-10-08","epss":0.22774,"percentile":0.97683}],"urls":["https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/","https://kb.cert.org/vuls/id/720344","https://security.gentoo.org/glsa/202210-40","https://security.netapp.com/advisory/ntap-20220915-0009/","https://sqlite.org/releaselog/3_39_2.html","https://www.sqlite.org/cves.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-35737","description":"SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-24329","versionConstraint":"< 3.6.9-1~18.04ubuntu1.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-24329","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.13"],"available":[{"date":"2023-02-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"risk":10.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-24329"},"relatedVulnerabilities":[{"id":"CVE-2023-24329","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"urls":["https://github.com/python/cpython/issues/102153","https://github.com/python/cpython/pull/99421","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/","https://pointernull.com/security/python-url-parse-problem.html","https://security.netapp.com/advisory/ntap-20230324-0004/","https://www.kb.cert.org/vuls/id/127587","https://lists.debian.org/debian-lts-announce/2024/11/msg00005.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24329","description":"An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-24329","versionConstraint":"< 3.6.9-1~18.04ubuntu1.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-24329","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.13"],"available":[{"date":"2023-02-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"risk":10.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-24329"},"relatedVulnerabilities":[{"id":"CVE-2023-24329","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"urls":["https://github.com/python/cpython/issues/102153","https://github.com/python/cpython/pull/99421","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/","https://pointernull.com/security/python-url-parse-problem.html","https://security.netapp.com/advisory/ntap-20230324-0004/","https://www.kb.cert.org/vuls/id/127587","https://lists.debian.org/debian-lts-announce/2024/11/msg00005.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24329","description":"An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-24329","versionConstraint":"< 3.6.9-1~18.04ubuntu1.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-24329","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.13"],"available":[{"date":"2023-02-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"risk":10.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-24329"},"relatedVulnerabilities":[{"id":"CVE-2023-24329","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"urls":["https://github.com/python/cpython/issues/102153","https://github.com/python/cpython/pull/99421","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/","https://pointernull.com/security/python-url-parse-problem.html","https://security.netapp.com/advisory/ntap-20230324-0004/","https://www.kb.cert.org/vuls/id/127587","https://lists.debian.org/debian-lts-announce/2024/11/msg00005.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24329","description":"An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-24329","versionConstraint":"< 3.6.9-1~18.04ubuntu1.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-24329","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.13"],"available":[{"date":"2023-02-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"risk":10.2295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-24329"},"relatedVulnerabilities":[{"id":"CVE-2023-24329","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24329","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24329","date":"2026-10-08","epss":0.20459,"percentile":0.9745}],"urls":["https://github.com/python/cpython/issues/102153","https://github.com/python/cpython/pull/99421","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PEVICI7YNGGMSL3UCMWGE66QFLATH72/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSL6NSOAXWBJJ67XPLSSC74MNKZF3BBO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EM2XLZSTXG44TMFXF4E6VTGKR2MQCW3G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2NY75GFDZ5T6YPN44D3VMFT5SUVTOTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GR5US3BYILYJ4SKBV6YBNPRUBAL5P2CN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H23OSKC6UG6IWOQAUPW74YUHWRWVXJP7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTLGV2HYFF4AMYJL25VDIGAIHCU7UPA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWC4WGXER5P6Q75RFGL7QUTPP3N5JR7T/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZEHSXSCMA4WWQKXT6QV7AAR6SWNZ2VP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5SP4RT3RRS434ZS2HQKQJ3VZW7YPKYR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHHJHJRLEF3TDT2K3676CAUVRDD4CCMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PEUN6T22UJFXR7J5F6UUHCXXPKJ2DVHI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PURM5CFDABEWAIWZFD2MQ7ZJGCPYSQ44/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3J5N24ECS4B6MJDRO6UAYU6GPLYBDCL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QRQHN7RWJQJHYP6E5EKESOYP5VDSHZG4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RA2MBEEES6L46OD64OBSVUUMGKNGMOWW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4IDB5OAR5Y4UK3HLMZBW4WEL2B7YFMJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZH26JGNZ5XYPZ5SAU3NKSBSPRE5OHTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2MZOJYGFCB5PPT6AKMAU72N7QOYWLBP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UONZWLB4QVLQIY5CPDLEUEKH6WX4VQMC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTOAUJNDWZDRWVSXJ354AYZYKRMT56HU/","https://pointernull.com/security/python-url-parse-problem.html","https://security.netapp.com/advisory/ntap-20230324-0004/","https://www.kb.cert.org/vuls/id/127587","https://lists.debian.org/debian-lts-announce/2024/11/msg00005.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24329","description":"An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-4450","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-4450","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4450","date":"2026-10-08","epss":0.20287,"percentile":0.97419}],"risk":10.1435,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4450"},"relatedVulnerabilities":[{"id":"CVE-2022-4450","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4450","date":"2026-10-08","epss":0.20287,"percentile":0.97419}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=63bcf189be73a9cc1264059bed6f57974be74a83","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=bbcf509bd046b34cca19c766bbddc31683d0858b","https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4450","description":"The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and\ndecodes the \"name\" (e.g. \"CERTIFICATE\"), any header data and the payload data.\nIf the function succeeds then the \"name_out\", \"header\" and \"data\" arguments are\npopulated with pointers to buffers containing the relevant decoded data. The\ncaller is responsible for freeing those buffers. It is possible to construct a\nPEM file that results in 0 bytes of payload data. In this case PEM_read_bio_ex()\nwill return a failure code but will populate the header argument with a pointer\nto a buffer that has already been freed. If the caller also frees this buffer\nthen a double free will occur. This will most likely lead to a crash. This\ncould be exploited by an attacker who has the ability to supply malicious PEM\nfiles for parsing to achieve a denial of service attack.\n\nThe functions PEM_read_bio() and PEM_read() are simple wrappers around\nPEM_read_bio_ex() and therefore these functions are also directly affected.\n\nThese functions are also called indirectly by a number of other OpenSSL\nfunctions including PEM_X509_INFO_read_bio_ex() and\nSSL_CTX_use_serverinfo_file() which are also vulnerable. Some OpenSSL internal\nuses of these functions are not vulnerable because the caller does not free the\nheader argument if PEM_read_bio_ex() returns a failure code. These locations\ninclude the PEM_read_bio_TYPE() functions as well as the decoders introduced in\nOpenSSL 3.0.\n\nThe OpenSSL asn1parse command line application is also impacted by this issue."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-4450","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-4450","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4450","date":"2026-10-08","epss":0.20287,"percentile":0.97419}],"risk":10.1435,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4450"},"relatedVulnerabilities":[{"id":"CVE-2022-4450","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4450","cwe":"CWE-415","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4450","date":"2026-10-08","epss":0.20287,"percentile":0.97419}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=63bcf189be73a9cc1264059bed6f57974be74a83","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=bbcf509bd046b34cca19c766bbddc31683d0858b","https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4450","description":"The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and\ndecodes the \"name\" (e.g. \"CERTIFICATE\"), any header data and the payload data.\nIf the function succeeds then the \"name_out\", \"header\" and \"data\" arguments are\npopulated with pointers to buffers containing the relevant decoded data. The\ncaller is responsible for freeing those buffers. It is possible to construct a\nPEM file that results in 0 bytes of payload data. In this case PEM_read_bio_ex()\nwill return a failure code but will populate the header argument with a pointer\nto a buffer that has already been freed. If the caller also frees this buffer\nthen a double free will occur. This will most likely lead to a crash. This\ncould be exploited by an attacker who has the ability to supply malicious PEM\nfiles for parsing to achieve a denial of service attack.\n\nThe functions PEM_read_bio() and PEM_read() are simple wrappers around\nPEM_read_bio_ex() and therefore these functions are also directly affected.\n\nThese functions are also called indirectly by a number of other OpenSSL\nfunctions including PEM_X509_INFO_read_bio_ex() and\nSSL_CTX_use_serverinfo_file() which are also vulnerable. Some OpenSSL internal\nuses of these functions are not vulnerable because the caller does not free the\nheader argument if PEM_read_bio_ex() returns a failure code. These locations\ninclude the PEM_read_bio_TYPE() functions as well as the decoders introduced in\nOpenSSL 3.0.\n\nThe OpenSSL asn1parse command line application is also impacted by this issue."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h822-r4r5-v8jg","versionConstraint":">=2.9.0,<2.9.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h822-r4r5-v8jg","fix":{"state":"fixed","versions":["2.9.10"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14540","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14540","date":"2026-10-08","epss":0.10763,"percentile":0.95731}],"risk":10.11722,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-14540","https://github.com/FasterXML/jackson-databind/blob/master/release-notes/VERSION-2.x","https://github.com/FasterXML/jackson-databind/issues/2410","https://github.com/FasterXML/jackson-databind/issues/2449","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/a4f2c9fb36642a48912cdec6836ec00e497427717c5d377f8d7ccce6@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb@%3Ccommits.hbase.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://seclists.org/bugtraq/2019/Oct/6","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/d4983c740fec7d5576b207a8c30a63d3ea7443de","https://github.com/FasterXML/jackson-databind/commit/73c1c2cc76e6cdd7f3a5615cbe3207fe96e4d3db","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT","https://security.netapp.com/advisory/ntap-20191004-0002"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h822-r4r5-v8jg","description":"Polymorphic Typing issue in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-14540","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14540","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14540","date":"2026-10-08","epss":0.10763,"percentile":0.95731}],"urls":["https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://github.com/FasterXML/jackson-databind/blob/master/release-notes/VERSION-2.x","https://github.com/FasterXML/jackson-databind/issues/2410","https://github.com/FasterXML/jackson-databind/issues/2449","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69%40%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/a4f2c9fb36642a48912cdec6836ec00e497427717c5d377f8d7ccce6%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb%40%3Ccommits.hbase.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191004-0002/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14540","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5r5r-6hpj-8gg9","versionConstraint":">=2.0.0,<=2.9.10.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5r5r-6hpj-8gg9","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2023-11-22","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35728","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-35728","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-35728","date":"2026-10-08","epss":0.12504,"percentile":0.9613}],"risk":9.753120000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-35728","https://github.com/FasterXML/jackson-databind/issues/2999","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210129-0007/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/1ca0388c2fb37ac6a06f1c188ae89c41e3e15e84"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5r5r-6hpj-8gg9","description":"Serialization gadget exploit in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-35728","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35728","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-35728","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-35728","date":"2026-10-08","epss":0.12504,"percentile":0.9613}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2999","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210129-0007/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-35728","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl)."}]},{"artifact":{"id":"c1103d6297198441","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-0ubuntu2:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.2.11.dfsg-0ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=zlib","type":"deb","version":"1:1.2.11.dfsg-0ubuntu2","language":"","licenses":["sha256:176de9c848d59ea736369969db73dcbe025da6360dfba52ad034b52d9616b7c3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:1.2.11.dfsg-0ubuntu2.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-37434","versionConstraint":"< 1:1.2.11.dfsg-0ubuntu2.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"zlib","version":"1:1.2.11.dfsg-0ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-37434","fix":{"state":"fixed","versions":["1:1.2.11.dfsg-0ubuntu2.2"],"available":[{"date":"2022-08-17","kind":"advisory","version":"1:1.2.11.dfsg-0ubuntu2.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-37434","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37434","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37434","date":"2026-10-08","epss":0.18972,"percentile":0.97237}],"risk":9.486,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-37434"},"relatedVulnerabilities":[{"id":"CVE-2022-37434","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-37434","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37434","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37434","date":"2026-10-08","epss":0.18972,"percentile":0.97237}],"urls":["http://seclists.org/fulldisclosure/2022/Oct/37","http://seclists.org/fulldisclosure/2022/Oct/38","http://seclists.org/fulldisclosure/2022/Oct/41","http://seclists.org/fulldisclosure/2022/Oct/42","http://www.openwall.com/lists/oss-security/2022/08/05/2","http://www.openwall.com/lists/oss-security/2022/08/09/1","https://github.com/curl/curl/issues/9271","https://github.com/ivd38/zlib_overflow","https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063","https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d","https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1","https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764","https://lists.debian.org/debian-lts-announce/2022/09/msg00012.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/","https://security.netapp.com/advisory/ntap-20220901-0005/","https://security.netapp.com/advisory/ntap-20230427-0007/","https://support.apple.com/kb/HT213488","https://support.apple.com/kb/HT213489","https://support.apple.com/kb/HT213490","https://support.apple.com/kb/HT213491","https://support.apple.com/kb/HT213493","https://support.apple.com/kb/HT213494","https://www.debian.org/security/2022/dsa-5218","https://cert-portal.siemens.com/productcert/html/ssa-150063.html","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-470355.html","https://cert-portal.siemens.com/productcert/html/ssa-561322.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-37434","description":"zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference)."}]},{"artifact":{"id":"2a59eca20ffdbfcc","cpes":["cpe:2.3:a:com.google.code.gson:gson:2.7:*:*:*:*:*:*:*","cpe:2.3:a:com.google.gson:gson:2.7:*:*:*:*:*:*:*","cpe:2.3:a:google:gson:2.7:*:*:*:*:*:*:*","cpe:2.3:a:code:gson:2.7:*:*:*:*:*:*:*","cpe:2.3:a:gson:gson:2.7:*:*:*:*:*:*:*"],"name":"gson","purl":"pkg:maven/com.google.code.gson/gson@2.7","type":"java-archive","version":"2.7","language":"java","licenses":[],"metadata":{"pomGroupID":"com.google.code.gson","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/gson-2.7.jar","manifestName":"","pomArtifactID":"gson","archiveDigests":[{"value":"751f548c85fa49f330cecbb1875893f971b33c4e","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/gson-2.7.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.8.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4jrv-ppp4-jm57","versionConstraint":"<2.8.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.google.code.gson:gson","version":"2.7"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4jrv-ppp4-jm57","fix":{"state":"fixed","versions":["2.8.9"],"available":[{"date":"2022-05-21","kind":"first-observed","version":"2.8.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25647","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25647","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25647","date":"2026-10-08","epss":0.1223,"percentile":0.96079}],"risk":9.2948,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-25647","https://github.com/google/gson/pull/1991","https://github.com/google/gson/pull/1991/commits","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327","https://lists.debian.org/debian-lts-announce/2022/05/msg00015.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://lists.debian.org/debian-lts-announce/2022/09/msg00009.html","https://www.debian.org/security/2022/dsa-5227","https://security.netapp.com/advisory/ntap-20220901-0009"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4jrv-ppp4-jm57","description":"Deserialization of Untrusted Data in Gson"},"relatedVulnerabilities":[{"id":"CVE-2022-25647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25647","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25647","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25647","date":"2026-10-08","epss":0.1223,"percentile":0.96079}],"urls":["https://github.com/google/gson/pull/1991","https://github.com/google/gson/pull/1991/commits","https://lists.debian.org/debian-lts-announce/2022/05/msg00015.html","https://lists.debian.org/debian-lts-announce/2022/09/msg00009.html","https://security.netapp.com/advisory/ntap-20220901-0009/","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327","https://www.debian.org/security/2022/dsa-5227","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25647","description":"The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks."}]},{"artifact":{"id":"13a9ac46d72c9ab7","cpes":["cpe:2.3:a:unzip:unzip:6.0-21ubuntu1:*:*:*:*:*:*:*"],"name":"unzip","purl":"pkg:deb/ubuntu/unzip@6.0-21ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"6.0-21ubuntu1","language":"","licenses":["sha256:e4864130ae7765aa9424f558ca7ca8fa01c1674344ab83e4ceec749ccda76980"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/unzip/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/unzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/unzip.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/unzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/unzip.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/unzip.list"},{"path":"/var/lib/dpkg/info/unzip.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/unzip.postinst"},{"path":"/var/lib/dpkg/info/unzip.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/unzip.postrm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.0-21ubuntu1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1000035","versionConstraint":"< 6.0-21ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"unzip","version":"6.0-21ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-1000035","fix":{"state":"fixed","versions":["6.0-21ubuntu1.1"],"available":[{"date":"2020-12-16","kind":"advisory","version":"6.0-21ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-1000035","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000035","date":"2026-10-08","epss":0.30066,"percentile":0.98175}],"risk":9.019799999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-1000035"},"relatedVulnerabilities":[{"id":"CVE-2018-1000035","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000035","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000035","date":"2026-10-08","epss":0.30066,"percentile":0.98175}],"urls":["https://lists.debian.org/debian-lts-announce/2020/01/msg00026.html","https://sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-infozip-unzip/index.html","https://security.gentoo.org/glsa/202003-58"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000035","description":"A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-7264","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-7264","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"risk":8.6505,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-7264"},"relatedVulnerabilities":[{"id":"CVE-2024-7264","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/31/1","https://curl.se/docs/CVE-2024-7264.html","https://curl.se/docs/CVE-2024-7264.json","https://hackerone.com/reports/2629968","https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519","https://security.netapp.com/advisory/ntap-20240828-0008/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7264","description":"libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-7264","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-7264","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"risk":8.6505,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-7264"},"relatedVulnerabilities":[{"id":"CVE-2024-7264","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/31/1","https://curl.se/docs/CVE-2024-7264.html","https://curl.se/docs/CVE-2024-7264.json","https://hackerone.com/reports/2629968","https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519","https://security.netapp.com/advisory/ntap-20240828-0008/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7264","description":"libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gww7-p5w4-wrfv","versionConstraint":">=2.9.0,<=2.9.10.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gww7-p5w4-wrfv","fix":{"state":"fixed","versions":["2.9.10.2"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20330","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20330","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20330","date":"2026-10-08","epss":0.0864,"percentile":0.94984}],"risk":8.1216,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-20330","https://github.com/FasterXML/jackson-databind/issues/2526","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.10.1...jackson-databind-2.9.10.2","https://lists.apache.org/thread.html/r107c8737db39ec9ec4f4e7147b249e29be79170b9ef4b80528105a2d@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r2c77dd6ab8344285bd8e481b57cf3029965a4b0036eefccef74cdd44@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r3f8180d0d25a7c6473ebb9714b0c1d19a73f455ae70d0c5fefc17e6c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r428735963bee7cb99877b88d3228e28ec28af64646455c4f3e7a3c94@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r50f513772f12e1babf65c7c2b9c16425bac2d945351879e2e267517f@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5c14fdcabdeaba258857bcb67198652e4dce1d33ddc590cd81d82393@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5c3644c97f0434d1ceb48ff48897a67bdbf3baf7efbe7d04625425b3@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r5d3d10fdf28110da3f9ac1b7d08d7e252f98d7d37ce0a6bd139a2e4f@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r67f4d4c48197454b83d62afbed8bebbda3764e6e3a6e26a848961764@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r707d23bb9ee245f50aa909add0da6e8d8f24719b1278ddd99d2428b2@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7a0821b44247a1e6c6fe5f2943b90ebc4f80a8d1fb0aa9a8b29a59a2@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7fb123e7dad49af5886cfec7135c0fd5b74e4c67af029e1dc91ba744@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r8831b7fa5ca87a1cf23ee08d6dedb7877a964c1d2bd869af24056a63@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r909c822409a276ba04dc2ae31179b16f6864ba02c4f9911bdffebf95@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra2e572f568de8df5ba151e6aebb225a0629faaf0476bf7c7ed877af8@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra5ce96faec37c26b0aa15b4b6a8b1cbb145a748653e56ae83e9685d0@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra8a80dbc7319916946397823aec0d893d24713cbf7b5aee0e957298c@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb532fed78d031fff477fd840b81946f6d1200f93a63698dae65aa528@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rd1f346227e11fc515914f3a7b20d81543e51e5822ba71baa0452634a@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd49cfa41bbb71ef33b53736a6af2aa8ba88c2106e30f2a34902a87d2@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd6c6fef14944f3dcfb58d35f9317eb1c32a700e86c1b5231e45d3d0b@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rfa57d9c2a27d3af14c69607fb1a3da00e758b2092aa88eb6a51b6e99@%3Cissues.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/eb254813cc822d0af015ce8fe05febf50721dc53","https://github.com/FasterXML/jackson-databind/commit/fc4214a883dc087070f25da738ef0d49c2f3387e","https://security.netapp.com/advisory/ntap-20200127-0004"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gww7-p5w4-wrfv","description":"Deserialization of Untrusted Data in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-20330","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20330","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20330","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20330","date":"2026-10-08","epss":0.0864,"percentile":0.94984}],"urls":["https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.10.1...jackson-databind-2.9.10.2","https://github.com/FasterXML/jackson-databind/issues/2526","https://lists.apache.org/thread.html/r107c8737db39ec9ec4f4e7147b249e29be79170b9ef4b80528105a2d%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r2c77dd6ab8344285bd8e481b57cf3029965a4b0036eefccef74cdd44%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r3f8180d0d25a7c6473ebb9714b0c1d19a73f455ae70d0c5fefc17e6c%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r428735963bee7cb99877b88d3228e28ec28af64646455c4f3e7a3c94%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r50f513772f12e1babf65c7c2b9c16425bac2d945351879e2e267517f%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5c14fdcabdeaba258857bcb67198652e4dce1d33ddc590cd81d82393%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5c3644c97f0434d1ceb48ff48897a67bdbf3baf7efbe7d04625425b3%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r5d3d10fdf28110da3f9ac1b7d08d7e252f98d7d37ce0a6bd139a2e4f%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r67f4d4c48197454b83d62afbed8bebbda3764e6e3a6e26a848961764%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r707d23bb9ee245f50aa909add0da6e8d8f24719b1278ddd99d2428b2%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7a0821b44247a1e6c6fe5f2943b90ebc4f80a8d1fb0aa9a8b29a59a2%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7fb123e7dad49af5886cfec7135c0fd5b74e4c67af029e1dc91ba744%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r8831b7fa5ca87a1cf23ee08d6dedb7877a964c1d2bd869af24056a63%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r909c822409a276ba04dc2ae31179b16f6864ba02c4f9911bdffebf95%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra2e572f568de8df5ba151e6aebb225a0629faaf0476bf7c7ed877af8%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra5ce96faec37c26b0aa15b4b6a8b1cbb145a748653e56ae83e9685d0%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra8a80dbc7319916946397823aec0d893d24713cbf7b5aee0e957298c%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb532fed78d031fff477fd840b81946f6d1200f93a63698dae65aa528%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rd1f346227e11fc515914f3a7b20d81543e51e5822ba71baa0452634a%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd49cfa41bbb71ef33b53736a6af2aa8ba88c2106e30f2a34902a87d2%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd6c6fef14944f3dcfb58d35f9317eb1c32a700e86c1b5231e45d3d0b%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rfa57d9c2a27d3af14c69607fb1a3da00e758b2092aa88eb6a51b6e99%40%3Cissues.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html","https://security.netapp.com/advisory/ntap-20200127-0004/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20330","description":"FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-4304","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-4304","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4304","date":"2026-10-08","epss":0.16195,"percentile":0.96865}],"risk":8.0975,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4304"},"relatedVulnerabilities":[{"id":"CVE-2022-4304","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4304","date":"2026-10-08","epss":0.16195,"percentile":0.96865}],"urls":["https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4304","description":"A timing based side channel exists in the OpenSSL RSA Decryption implementation\nwhich could be sufficient to recover a plaintext across a network in a\nBleichenbacher style attack. To achieve a successful decryption an attacker\nwould have to be able to send a very large number of trial messages for\ndecryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5,\nRSA-OEAP and RSASVE.\n\nFor example, in a TLS connection, RSA is commonly used by a client to send an\nencrypted pre-master secret to the server. An attacker that had observed a\ngenuine connection between a client and a server could use this flaw to send\ntrial messages to the server and record the time taken to process them. After a\nsufficiently large number of messages the attacker could recover the pre-master\nsecret used for the original connection and thus be able to decrypt the\napplication data sent over that connection."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-4304","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-4304","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4304","date":"2026-10-08","epss":0.16195,"percentile":0.96865}],"risk":8.0975,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4304"},"relatedVulnerabilities":[{"id":"CVE-2022-4304","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4304","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4304","date":"2026-10-08","epss":0.16195,"percentile":0.96865}],"urls":["https://security.gentoo.org/glsa/202402-08","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4304","description":"A timing based side channel exists in the OpenSSL RSA Decryption implementation\nwhich could be sufficient to recover a plaintext across a network in a\nBleichenbacher style attack. To achieve a successful decryption an attacker\nwould have to be able to send a very large number of trial messages for\ndecryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5,\nRSA-OEAP and RSASVE.\n\nFor example, in a TLS connection, RSA is commonly used by a client to send an\nencrypted pre-master secret to the server. An attacker that had observed a\ngenuine connection between a client and a server could use this flaw to send\ntrial messages to the server and record the time taken to process them. After a\nsufficiently large number of messages the attacker could recover the pre-master\nsecret used for the original connection and thus be able to decrypt the\napplication data sent over that connection."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.30"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9xcj-c8cr-8c3c","versionConstraint":">=9.0.0,<9.0.30 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9xcj-c8cr-8c3c","fix":{"state":"fixed","versions":["9.0.30"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"9.0.30"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17563","cwe":"CWE-384","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17563","date":"2026-10-08","epss":0.10687,"percentile":0.95709}],"risk":8.01525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-17563","https://lists.apache.org/thread.html/8b4c1db8300117b28a0f3f743c0b9e3f964687a690cdf9662a884bbd%40%3Cannounce.tomcat.apache.org%3E","https://seclists.org/bugtraq/2019/Dec/43","https://www.debian.org/security/2019/dsa-4596","https://security.netapp.com/advisory/ntap-20200107-0001/","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.html","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/01/msg00024.html","https://usn.ubuntu.com/4251-1/","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://security.gentoo.org/glsa/202003-43","https://www.debian.org/security/2020/dsa-4680","https://www.oracle.com/security-alerts/cpuapr2020.html","https://lists.apache.org/thread.html/reb9a66f176df29b9a832caa95ebd9ffa3284e8f4922ec4fa3ad8eb2e@%3Cissues.cxf.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9xcj-c8cr-8c3c","description":"In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack"},"relatedVulnerabilities":[{"id":"CVE-2019-17563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"impactScore":6.5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17563","cwe":"CWE-384","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17563","date":"2026-10-08","epss":0.10687,"percentile":0.95709}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.html","https://lists.apache.org/thread.html/8b4c1db8300117b28a0f3f743c0b9e3f964687a690cdf9662a884bbd%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/reb9a66f176df29b9a832caa95ebd9ffa3284e8f4922ec4fa3ad8eb2e%40%3Cissues.cxf.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/01/msg00024.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://seclists.org/bugtraq/2019/Dec/43","https://security.gentoo.org/glsa/202003-43","https://security.netapp.com/advisory/ntap-20200107-0001/","https://usn.ubuntu.com/4251-1/","https://www.debian.org/security/2019/dsa-4596","https://www.debian.org/security/2020/dsa-4680","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-17563","description":"When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35559","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35559","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-35559","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35559","date":"2026-10-08","epss":0.159,"percentile":0.96812}],"risk":7.95,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35559"},"relatedVulnerabilities":[{"id":"CVE-2021-35559","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-35559","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35559","date":"2026-10-08","epss":0.159,"percentile":0.96812}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35559","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.9.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwp4-hfv6-p7hw","versionConstraint":">=2.9.0,<2.9.9.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gwp4-hfv6-p7hw","fix":{"state":"fixed","versions":["2.9.9.2"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.9.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14439","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14439","date":"2026-10-08","epss":0.10564,"percentile":0.95674}],"risk":7.922999999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-14439","https://github.com/FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2","https://github.com/FasterXML/jackson-databind/issues/2389","https://access.redhat.com/errata/RHSA-2019:3200","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20190814-0001/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwp4-hfv6-p7hw","description":"Deserialization of untrusted data in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-14439","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14439","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14439","date":"2026-10-08","epss":0.10564,"percentile":0.95674}],"urls":["https://access.redhat.com/errata/RHSA-2019:3200","https://github.com/FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2","https://github.com/FasterXML/jackson-databind/issues/2389","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef%40%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20190814-0001/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14439","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.9.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6fpp-rgj9-8rwc","versionConstraint":">=2.9.0,<2.9.9.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6fpp-rgj9-8rwc","fix":{"state":"fixed","versions":["2.9.9.2"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.9.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14379","cwe":"CWE-1321","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14379","date":"2026-10-08","epss":0.08111,"percentile":0.94695}],"risk":7.62434,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-14379","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2","https://github.com/FasterXML/jackson-databind/issues/2387","https://access.redhat.com/errata/RHBA-2019:2824","https://access.redhat.com/errata/RHSA-2019:2743","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/2766188be238a446a250ef76801037d452979152d85bce5e46805815@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/525bcf949a4b0da87a375cbad2680b8beccde749522f24c49befe7fb@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/689c6bcc6c7612eee71e453a115a4c8581e7b718537025d4b265783d@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/75f482fdc84abe6d0c8f438a76437c335a7bbeb5cddd4d70b4bc0cbf@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/859815b2e9f1575acbb2b260b73861c16ca49bca627fa0c46419051f@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/8723b52c2544e6cb804bc8a36622c584acd1bd6c53f2b6034c9fea54@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/99944f86abefde389da9b4040ea2327c6aa0b53a2ff9352bd4cfec17@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/d161ff3d59c5a8213400dd6afb1cce1fac4f687c32d1e0c0bfbfaa2d@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/e25e734c315f70d8876a846926cfe3bfa1a4888044f146e844caf72f@%3Ccommits.ambari.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f17f63b0f8a57e4a5759e01d25cffc0548f0b61ff5c6bfd704ad2f2a@%3Ccommits.ambari.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/","https://security.netapp.com/advisory/ntap-20190814-0001/","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2020:0727","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://support.apple.com/kb/HT213189","http://seclists.org/fulldisclosure/2022/Mar/23","https://github.com/FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6fpp-rgj9-8rwc","description":"Deserialization of untrusted data in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-14379","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14379","cwe":"CWE-1321","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14379","date":"2026-10-08","epss":0.08111,"percentile":0.94695}],"urls":["http://seclists.org/fulldisclosure/2022/Mar/23","https://access.redhat.com/errata/RHBA-2019:2824","https://access.redhat.com/errata/RHSA-2019:2743","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2020:0727","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2","https://github.com/FasterXML/jackson-databind/issues/2387","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69%40%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/2766188be238a446a250ef76801037d452979152d85bce5e46805815%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/525bcf949a4b0da87a375cbad2680b8beccde749522f24c49befe7fb%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/689c6bcc6c7612eee71e453a115a4c8581e7b718537025d4b265783d%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/75f482fdc84abe6d0c8f438a76437c335a7bbeb5cddd4d70b4bc0cbf%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/859815b2e9f1575acbb2b260b73861c16ca49bca627fa0c46419051f%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/8723b52c2544e6cb804bc8a36622c584acd1bd6c53f2b6034c9fea54%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef%40%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/99944f86abefde389da9b4040ea2327c6aa0b53a2ff9352bd4cfec17%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/d161ff3d59c5a8213400dd6afb1cce1fac4f687c32d1e0c0bfbfaa2d%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/e25e734c315f70d8876a846926cfe3bfa1a4888044f146e844caf72f%40%3Ccommits.ambari.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f17f63b0f8a57e4a5759e01d25cffc0548f0b61ff5c6bfd704ad2f2a%40%3Ccommits.ambari.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/","https://security.netapp.com/advisory/ntap-20190814-0001/","https://support.apple.com/kb/HT213189","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14379","description":"SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution."}]},{"artifact":{"id":"3445236446ec4939","cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"krb5-locales","purl":"pkg:deb/ubuntu/krb5-locales@1.16-2ubuntu0.1?arch=all&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-3596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-3596","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"risk":7.4295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-3596"},"relatedVulnerabilities":[{"id":"CVE-2024-3596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/09/4","https://cert-portal.siemens.com/productcert/html/ssa-723487.html","https://cert-portal.siemens.com/productcert/html/ssa-794185.html","https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/","https://datatracker.ietf.org/doc/html/rfc2865","https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014","https://www.blastradius.fail/","https://security.netapp.com/advisory/ntap-20240822-0001/","https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol","https://www.kb.cert.org/vuls/id/456537","https://cert-portal.siemens.com/productcert/html/ssa-364175.html","https://cert-portal.siemens.com/productcert/html/ssa-770770.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-3596","description":"RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature."}]},{"artifact":{"id":"f3fc35a2cb3401bd","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/ubuntu/libgssapi-krb5-2@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-3596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-3596","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"risk":7.4295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-3596"},"relatedVulnerabilities":[{"id":"CVE-2024-3596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/09/4","https://cert-portal.siemens.com/productcert/html/ssa-723487.html","https://cert-portal.siemens.com/productcert/html/ssa-794185.html","https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/","https://datatracker.ietf.org/doc/html/rfc2865","https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014","https://www.blastradius.fail/","https://security.netapp.com/advisory/ntap-20240822-0001/","https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol","https://www.kb.cert.org/vuls/id/456537","https://cert-portal.siemens.com/productcert/html/ssa-364175.html","https://cert-portal.siemens.com/productcert/html/ssa-770770.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-3596","description":"RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature."}]},{"artifact":{"id":"ce64c2275844a0e2","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/ubuntu/libk5crypto3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-3596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-3596","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"risk":7.4295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-3596"},"relatedVulnerabilities":[{"id":"CVE-2024-3596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/09/4","https://cert-portal.siemens.com/productcert/html/ssa-723487.html","https://cert-portal.siemens.com/productcert/html/ssa-794185.html","https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/","https://datatracker.ietf.org/doc/html/rfc2865","https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014","https://www.blastradius.fail/","https://security.netapp.com/advisory/ntap-20240822-0001/","https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol","https://www.kb.cert.org/vuls/id/456537","https://cert-portal.siemens.com/productcert/html/ssa-364175.html","https://cert-portal.siemens.com/productcert/html/ssa-770770.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-3596","description":"RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature."}]},{"artifact":{"id":"a0e77fe46f00e692","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/ubuntu/libkrb5-3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-3596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-3596","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"risk":7.4295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-3596"},"relatedVulnerabilities":[{"id":"CVE-2024-3596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/09/4","https://cert-portal.siemens.com/productcert/html/ssa-723487.html","https://cert-portal.siemens.com/productcert/html/ssa-794185.html","https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/","https://datatracker.ietf.org/doc/html/rfc2865","https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014","https://www.blastradius.fail/","https://security.netapp.com/advisory/ntap-20240822-0001/","https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol","https://www.kb.cert.org/vuls/id/456537","https://cert-portal.siemens.com/productcert/html/ssa-364175.html","https://cert-portal.siemens.com/productcert/html/ssa-770770.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-3596","description":"RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature."}]},{"artifact":{"id":"402827dd4cb6593f","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/ubuntu/libkrb5support0@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-3596","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-3596","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"risk":7.4295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-3596"},"relatedVulnerabilities":[{"id":"CVE-2024-3596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"impactScore":6.1,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-3596","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-3596","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-3596","date":"2026-10-08","epss":0.14859,"percentile":0.9662}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/09/4","https://cert-portal.siemens.com/productcert/html/ssa-723487.html","https://cert-portal.siemens.com/productcert/html/ssa-794185.html","https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/","https://datatracker.ietf.org/doc/html/rfc2865","https://networkradius.com/assets/pdf/radius_and_md5_collisions.pdf","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0014","https://www.blastradius.fail/","https://security.netapp.com/advisory/ntap-20240822-0001/","https://today.ucsd.edu/story/computer-scientists-discover-vulnerabilities-in-a-popular-security-protocol","https://www.kb.cert.org/vuls/id/456537","https://cert-portal.siemens.com/productcert/html/ssa-364175.html","https://cert-portal.siemens.com/productcert/html/ssa-770770.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-3596","description":"RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.44"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f4qf-m5gf-8jm8","versionConstraint":">=9.0.0-M11,<9.0.44 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-f4qf-m5gf-8jm8","fix":{"state":"fixed","versions":["9.0.44"],"available":[{"date":"2026-06-19","kind":"first-observed","version":"9.0.44"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-21733","cwe":"CWE-209","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-21733","date":"2026-10-08","epss":0.14286,"percentile":0.9652}],"risk":7.35729,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-21733","https://lists.apache.org/thread/h9bjqdd0odj6lhs2o96qgowcc6hb0cfz","http://www.openwall.com/lists/oss-security/2024/01/19/2","http://packetstormsecurity.com/files/176951/Apache-Tomcat-8.5.63-9.0.43-HTTP-Response-Smuggling.html","https://security.netapp.com/advisory/ntap-20240216-0005","https://github.com/apache/tomcat/commit/86ccc43940861703c2be96a5f35384407522125a","https://github.com/apache/tomcat/commit/ce4b154e7b48f66bd98858626347747cd2514311","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-9.html","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f4qf-m5gf-8jm8","description":"Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information"},"relatedVulnerabilities":[{"id":"CVE-2024-21733","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-21733","cwe":"CWE-209","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-21733","date":"2026-10-08","epss":0.14286,"percentile":0.9652}],"urls":["https://lists.apache.org/thread/h9bjqdd0odj6lhs2o96qgowcc6hb0cfz","http://packetstormsecurity.com/files/176951/Apache-Tomcat-8.5.63-9.0.43-HTTP-Response-Smuggling.html","http://www.openwall.com/lists/oss-security/2024/01/19/2","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html","https://security.netapp.com/advisory/ntap-20240216-0005/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-21733","description":"Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected.\n\nUsers are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.41"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jgwr-3qm3-26f3","versionConstraint":">=9.0.0,<9.0.41 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jgwr-3qm3-26f3","fix":{"state":"fixed","versions":["9.0.41"],"available":[{"date":"2021-03-20","kind":"first-observed","version":"9.0.41"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-25329","date":"2026-10-08","epss":0.09491,"percentile":0.95325}],"risk":6.8809749999999985,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-25329","https://github.com/apache/tomcat/commit/6d66e99ef85da93e4d2c2a536ca51aa3418bfaf4","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cusers.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","http://www.openwall.com/lists/oss-security/2021/03/01/2","https://security.netapp.com/advisory/ntap-20210409-0002/","https://www.debian.org/security/2021/dsa-4891","https://lists.apache.org/thread.html/r732b2ca289dc02df2de820e8775559abd6c207f159e39f559547a085@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77@%3Cusers.tomcat.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://security.gentoo.org/glsa/202208-34"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jgwr-3qm3-26f3","description":"Potential remote code execution in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2021-25329","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"impactScore":6.5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-25329","date":"2026-10-08","epss":0.09491,"percentile":0.95325}],"urls":["http://www.openwall.com/lists/oss-security/2021/03/01/2","https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r732b2ca289dc02df2de820e8775559abd6c207f159e39f559547a085%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/03/msg00018.html","https://security.gentoo.org/glsa/202208-34","https://security.netapp.com/advisory/ntap-20210409-0002/","https://www.debian.org/security/2021/dsa-4891","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-25329","description":"The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f9xh-2qgp-cq57","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-f9xh-2qgp-cq57","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36188","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36188","date":"2026-10-08","epss":0.08787,"percentile":0.95056}],"risk":6.853860000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36188","https://github.com/FasterXML/jackson-databind/issues/2996","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f9xh-2qgp-cq57","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36188","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36188","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36188","date":"2026-10-08","epss":0.08787,"percentile":0.95056}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2996","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36188","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j823-4qch-3rgm","versionConstraint":">=2.9.0,<=2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j823-4qch-3rgm","fix":{"state":"fixed","versions":["2.9.10.5"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14060","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14060","date":"2026-10-08","epss":0.08607,"percentile":0.94968}],"risk":6.71346,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-14060","https://github.com/FasterXML/jackson-databind/issues/2688","https://github.com/FasterXML/jackson-databind/commit/d1c67a0396e84c08d0558fbb843b5bd1f26e1921","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/ac7232e3f9004bdb4f11dcb5bc6c1fadf074f5f7","https://security.netapp.com/advisory/ntap-20200702-0003","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j823-4qch-3rgm","description":"Deserialization of untrusted data in Jackson Databind"},"relatedVulnerabilities":[{"id":"CVE-2020-14060","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14060","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14060","date":"2026-10-08","epss":0.08607,"percentile":0.94968}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2688","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200702-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14060","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill)."}]},{"artifact":{"id":"e323d40f321cd758","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:237-3ubuntu10.39:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@237-3ubuntu10.39?arch=amd64&distro=ubuntu-18.04&upstream=systemd","type":"deb","version":"237-3ubuntu10.39","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"237-3ubuntu10.49"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-33910","versionConstraint":"< 237-3ubuntu10.49 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"systemd","version":"237-3ubuntu10.39"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-33910","fix":{"state":"fixed","versions":["237-3ubuntu10.49"],"available":[{"date":"2021-07-20","kind":"advisory","version":"237-3ubuntu10.49"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-08","epss":0.08792,"percentile":0.95058}],"risk":6.593999999999999,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33910"},"relatedVulnerabilities":[{"id":"CVE-2021-33910","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-08","epss":0.08792,"percentile":0.95058}],"urls":["http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html","http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf","https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b","https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce","https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538","https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61","https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b","https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20211104-0008/","https://www.debian.org/security/2021/dsa-4942","https://www.openwall.com/lists/oss-security/2021/07/20/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33910","description":"basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash."}]},{"artifact":{"id":"37df44b4b8f9c551","cpes":["cpe:2.3:a:libudev1:libudev1:237-3ubuntu10.39:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@237-3ubuntu10.39?arch=amd64&distro=ubuntu-18.04&upstream=systemd","type":"deb","version":"237-3ubuntu10.39","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"237-3ubuntu10.49"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-33910","versionConstraint":"< 237-3ubuntu10.49 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"systemd","version":"237-3ubuntu10.39"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-33910","fix":{"state":"fixed","versions":["237-3ubuntu10.49"],"available":[{"date":"2021-07-20","kind":"advisory","version":"237-3ubuntu10.49"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-08","epss":0.08792,"percentile":0.95058}],"risk":6.593999999999999,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-33910"},"relatedVulnerabilities":[{"id":"CVE-2021-33910","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-33910","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-33910","date":"2026-10-08","epss":0.08792,"percentile":0.95058}],"urls":["http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.html","http://www.openwall.com/lists/oss-security/2021/08/04/2","http://www.openwall.com/lists/oss-security/2021/08/17/3","http://www.openwall.com/lists/oss-security/2021/09/07/3","https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf","https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b","https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce","https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538","https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61","https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896b","https://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/","https://security.gentoo.org/glsa/202107-48","https://security.netapp.com/advisory/ntap-20211104-0008/","https://www.debian.org/security/2021/dsa-4942","https://www.openwall.com/lists/oss-security/2021/07/20/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-33910","description":"basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.98"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-27hp-xhwr-wr2m","versionConstraint":">=9.0.0.M1,<9.0.98 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-27hp-xhwr-wr2m","fix":{"state":"fixed","versions":["9.0.98"],"available":[{"date":"2025-01-09","kind":"first-observed","version":"9.0.98"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56337","cwe":"CWE-367","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-56337","date":"2026-10-08","epss":0.08969,"percentile":0.95141}],"risk":6.5922149999999995,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-56337","https://lists.apache.org/thread/b2b9qrgjrz1kvo4ym8y2wkfdvwoq6qbp","https://www.cve.org/CVERecord?id=CVE-2024-50379","https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.34","https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.2","https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.98","https://security.netapp.com/advisory/ntap-20250103-0002","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-27hp-xhwr-wr2m","description":"Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-56337","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56337","cwe":"CWE-367","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-56337","date":"2026-10-08","epss":0.08969,"percentile":0.95141}],"urls":["https://lists.apache.org/thread/b2b9qrgjrz1kvo4ym8y2wkfdvwoq6qbp","https://www.cve.org/CVERecord?id=CVE-2024-50379","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html","https://security.netapp.com/advisory/ntap-20250103-0002/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56337","description":"Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nThe mitigation for CVE-2024-50379 was incomplete.\n\nUsers running Tomcat on a case insensitive file system with the default servlet write enabled (readonly initialisation \nparameter set to the non-default value of false) may need additional configuration to fully mitigate CVE-2024-50379 depending on which version of Java they are using with Tomcat:\n- running on Java 8 or Java 11: the system property sun.io.useCanonCaches must be explicitly set to false (it defaults to true)\n- running on Java 17: the system property sun.io.useCanonCaches, if set, must be set to false (it defaults to false)\n- running on Java 21 onwards: no further configuration is required (the system property and the problematic cache have been removed)\n\nTomcat 11.0.3, 10.1.35 and 9.0.99 onwards will include checks that sun.io.useCanonCaches is set appropriately before allowing the default servlet to be write enabled on a case insensitive file system. Tomcat will also set sun.io.useCanonCaches to false by default where it can."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fqwf-pjwf-7vqv","versionConstraint":">=2.7.0,<2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-fqwf-pjwf-7vqv","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10673","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10673","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10673","date":"2026-10-08","epss":0.08028,"percentile":0.94643}],"risk":6.542820000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10673","https://github.com/FasterXML/jackson-databind/issues/2660","https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/1645efbd392989cf015f459a91c999e59c921b15","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fqwf-pjwf-7vqv","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-10673","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10673","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10673","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10673","date":"2026-10-08","epss":0.08028,"percentile":0.94643}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2660","https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10673","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m6x4-97wx-4q27","versionConstraint":">=2.0.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-m6x4-97wx-4q27","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36184","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36184","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36184","date":"2026-10-08","epss":0.08356,"percentile":0.94829}],"risk":6.5176799999999995,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36184","https://github.com/FasterXML/jackson-databind/issues/2998","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/567194c53ae91f0a14dc27239afb739b1c10448a"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m6x4-97wx-4q27","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36184","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36184","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36184","date":"2026-10-08","epss":0.08356,"percentile":0.94829}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2998","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36184","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c265-37vj-cwcc","versionConstraint":">=2.9.0,<=2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c265-37vj-cwcc","fix":{"state":"fixed","versions":["2.9.10.5"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14062","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14062","date":"2026-10-08","epss":0.08108,"percentile":0.94694}],"risk":6.3242400000000005,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-14062","https://github.com/FasterXML/jackson-databind/issues/2704","https://github.com/FasterXML/jackson-databind/commit/99001cdb6807b5c7b170ec6a9092ecbb618ae79c","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/840eae2ca81c597a0010b2126f32dce17d384b70","https://security.netapp.com/advisory/ntap-20200702-0003","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c265-37vj-cwcc","description":"Deserialization of untrusted data in Jackson Databind"},"relatedVulnerabilities":[{"id":"CVE-2020-14062","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14062","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14062","date":"2026-10-08","epss":0.08108,"percentile":0.94694}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2704","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200702-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14062","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r3gr-cxrf-hg25","versionConstraint":">=2.0.0,<=2.9.10.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r3gr-cxrf-hg25","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35491","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-35491","date":"2026-10-08","epss":0.0775,"percentile":0.94492}],"risk":6.045,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-35491","https://github.com/FasterXML/jackson-databind/issues/2986","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/41b8bdb5ccc1d8edb71acf1c8234da235a24249d","https://security.netapp.com/advisory/ntap-20210122-0005"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r3gr-cxrf-hg25","description":"Serialization gadgets exploit in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-35491","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35491","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-35491","date":"2026-10-08","epss":0.0775,"percentile":0.94492}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2986","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210122-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-35491","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36230","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36230","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36230","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36230","date":"2026-10-08","epss":0.11968,"percentile":0.96027}],"risk":5.984,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36230"},"relatedVulnerabilities":[{"id":"CVE-2020-36230","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36230","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36230","date":"2026-10-08","epss":0.11968,"percentile":0.96027}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9423","https://git.openldap.org/openldap/openldap/-/commit/8c1d96ee36ed98b32cd0e28b7069c7b8ea09d793","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36230","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36230","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36230","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36230","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36230","date":"2026-10-08","epss":0.11968,"percentile":0.96027}],"risk":5.984,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36230"},"relatedVulnerabilities":[{"id":"CVE-2020-36230","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36230","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36230","date":"2026-10-08","epss":0.11968,"percentile":0.96027}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9423","https://git.openldap.org/openldap/openldap/-/commit/8c1d96ee36ed98b32cd0e28b7069c7b8ea09d793","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36230","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cmfg-87vq-g5g4","versionConstraint":">=2.9.0,<2.9.9.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cmfg-87vq-g5g4","fix":{"state":"fixed","versions":["2.9.9.1"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12814","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-12814","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-12814","date":"2026-10-08","epss":0.10902,"percentile":0.95774}],"risk":5.941590000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-12814","https://github.com/FasterXML/jackson-databind/issues/2341","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/129da0204c876f746636018751a086cc581e0e07bcdeb3ee22ff5731@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/15a55e1d837fa686db493137cc0330c7ee1089ed9a9eea7ae7151ef1@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/1e04d9381c801b31ab28dec813c31c304b2a596b2a3707fa5462c5c0@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/28be28ffd6471d230943a255c36fe196a54ef5afc494a4781d16e37c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2ff264b6a94c5363a35c4c88fa93216f60ec54d1d973ed6b76a9f560@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/4b832d1327703d6b287a6d223307f8f884d798821209a10647e93324@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/71f9ffd92410a889e27b95a219eaa843fd820f8550898633d85d4ea3@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/8fe2983f6d9fee0aa737e4bd24483f8f5cf9b938b9adad0c4e79b2a4@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/a3ae8a8c5e32c413cd27071d3a204166050bf79ce7f1299f6866338f@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/a62aa2706105d68f1c02023fe24aaa3c13b4d8a1826181fed07d9682@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/a78239b1f11cddfa86e4edee19064c40b6272214630bfef070c37957@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0a2b2cca072650dbd5882719976c3d353972c44f6736ddf0ba95209@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/b148fa2e9ef468c4de00de255dd728b74e2a97d935f8ced31eb41ba2@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/bf20574dbc2db255f1fd489942b5720f675e32a2c4f44eb6a36060cd@%3Ccommits.accumulo.apache.org%3E","https://lists.apache.org/thread.html/e0733058c0366b703e6757d8d2a7a04b943581f659e9c271f0841dfe@%3Cnotifications.geode.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/eff7280055fc717ea8129cd28a9dd57b8446d00b36260c1caee10b87@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00019.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/5f7c69bba07a7155adde130d9dee2e54a54f1fa5","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC","https://security.netapp.com/advisory/ntap-20190625-0006"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cmfg-87vq-g5g4","description":"Deserialization of untrusted data in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-12814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12814","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-12814","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-12814","date":"2026-10-08","epss":0.10902,"percentile":0.95774}],"urls":["https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://github.com/FasterXML/jackson-databind/issues/2341","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/129da0204c876f746636018751a086cc581e0e07bcdeb3ee22ff5731%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/15a55e1d837fa686db493137cc0330c7ee1089ed9a9eea7ae7151ef1%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/1e04d9381c801b31ab28dec813c31c304b2a596b2a3707fa5462c5c0%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/28be28ffd6471d230943a255c36fe196a54ef5afc494a4781d16e37c%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2ff264b6a94c5363a35c4c88fa93216f60ec54d1d973ed6b76a9f560%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/4b832d1327703d6b287a6d223307f8f884d798821209a10647e93324%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/71f9ffd92410a889e27b95a219eaa843fd820f8550898633d85d4ea3%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/8fe2983f6d9fee0aa737e4bd24483f8f5cf9b938b9adad0c4e79b2a4%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef%40%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/a3ae8a8c5e32c413cd27071d3a204166050bf79ce7f1299f6866338f%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/a62aa2706105d68f1c02023fe24aaa3c13b4d8a1826181fed07d9682%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/a78239b1f11cddfa86e4edee19064c40b6272214630bfef070c37957%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0a2b2cca072650dbd5882719976c3d353972c44f6736ddf0ba95209%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/b148fa2e9ef468c4de00de255dd728b74e2a97d935f8ced31eb41ba2%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/bf20574dbc2db255f1fd489942b5720f675e32a2c4f44eb6a36060cd%40%3Ccommits.accumulo.apache.org%3E","https://lists.apache.org/thread.html/e0733058c0366b703e6757d8d2a7a04b943581f659e9c271f0841dfe%40%3Cnotifications.geode.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/eff7280055fc717ea8129cd28a9dd57b8446d00b36260c1caee10b87%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/","https://security.netapp.com/advisory/ntap-20190625-0006/","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12814","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h3cw-g4mq-c5x2","versionConstraint":">=2.0.0,<=2.9.10.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h3cw-g4mq-c5x2","fix":{"state":"fixed","versions":["2.9.10.6"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-24616","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-24616","date":"2026-10-08","epss":0.0758,"percentile":0.94386}],"risk":5.912400000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-24616","https://github.com/FasterXML/jackson-databind/issues/2814","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://github.com/FasterXML/jackson-databind/commit/3d97153944f7de9c19c1b3637b33d3cf1fbbe4d7"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h3cw-g4mq-c5x2","description":"Code Injection in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-24616","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-24616","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-24616","date":"2026-10-08","epss":0.0758,"percentile":0.94386}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2814","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-24616","description":"FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5949-rw7g-wx7w","versionConstraint":">=2.7.0,<2.9.10.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5949-rw7g-wx7w","fix":{"state":"fixed","versions":["2.9.10.7"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-20190","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-20190","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-20190","date":"2026-10-08","epss":0.07483,"percentile":0.94328}],"risk":5.83674,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-20190","https://github.com/FasterXML/jackson-databind/issues/2854","https://github.com/FasterXML/jackson-databind/commit/7dbf51bf78d157098074a20bd9da39bd48c18e4a","https://bugzilla.redhat.com/show_bug.cgi?id=1916633","https://lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://security.netapp.com/advisory/ntap-20210219-0008"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5949-rw7g-wx7w","description":"Deserialization of untrusted data in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2021-20190","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:C","metrics":{"baseScore":8.3,"impactScore":8.6,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-20190","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-20190","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-20190","date":"2026-10-08","epss":0.07483,"percentile":0.94328}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1916633","https://github.com/FasterXML/jackson-databind/issues/2854","https://lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a%40%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210219-0008/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-20190","description":"A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3737","versionConstraint":"< 3.6.9-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3737","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.6"],"available":[{"date":"2021-12-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3737","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3737","date":"2026-10-08","epss":0.11586,"percentile":0.95942}],"risk":5.793,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3737"},"relatedVulnerabilities":[{"id":"CVE-2021-3737","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3737","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3737","date":"2026-10-08","epss":0.11586,"percentile":0.95942}],"urls":["https://bugs.python.org/issue44022","https://bugzilla.redhat.com/show_bug.cgi?id=1995162","https://github.com/python/cpython/pull/25916","https://github.com/python/cpython/pull/26503","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/urllib-100-continue-loop.html","https://security.netapp.com/advisory/ntap-20220407-0009/","https://ubuntu.com/security/CVE-2021-3737","https://www.oracle.com/security-alerts/cpujul2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3737","description":"A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3737","versionConstraint":"< 3.6.9-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3737","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.6"],"available":[{"date":"2021-12-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3737","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3737","date":"2026-10-08","epss":0.11586,"percentile":0.95942}],"risk":5.793,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3737"},"relatedVulnerabilities":[{"id":"CVE-2021-3737","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3737","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3737","date":"2026-10-08","epss":0.11586,"percentile":0.95942}],"urls":["https://bugs.python.org/issue44022","https://bugzilla.redhat.com/show_bug.cgi?id=1995162","https://github.com/python/cpython/pull/25916","https://github.com/python/cpython/pull/26503","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/urllib-100-continue-loop.html","https://security.netapp.com/advisory/ntap-20220407-0009/","https://ubuntu.com/security/CVE-2021-3737","https://www.oracle.com/security-alerts/cpujul2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3737","description":"A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3737","versionConstraint":"< 3.6.9-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3737","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.6"],"available":[{"date":"2021-12-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3737","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3737","date":"2026-10-08","epss":0.11586,"percentile":0.95942}],"risk":5.793,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3737"},"relatedVulnerabilities":[{"id":"CVE-2021-3737","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3737","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3737","date":"2026-10-08","epss":0.11586,"percentile":0.95942}],"urls":["https://bugs.python.org/issue44022","https://bugzilla.redhat.com/show_bug.cgi?id=1995162","https://github.com/python/cpython/pull/25916","https://github.com/python/cpython/pull/26503","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/urllib-100-continue-loop.html","https://security.netapp.com/advisory/ntap-20220407-0009/","https://ubuntu.com/security/CVE-2021-3737","https://www.oracle.com/security-alerts/cpujul2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3737","description":"A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3737","versionConstraint":"< 3.6.9-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3737","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.6"],"available":[{"date":"2021-12-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3737","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3737","date":"2026-10-08","epss":0.11586,"percentile":0.95942}],"risk":5.793,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3737"},"relatedVulnerabilities":[{"id":"CVE-2021-3737","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3737","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3737","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3737","date":"2026-10-08","epss":0.11586,"percentile":0.95942}],"urls":["https://bugs.python.org/issue44022","https://bugzilla.redhat.com/show_bug.cgi?id=1995162","https://github.com/python/cpython/pull/25916","https://github.com/python/cpython/pull/26503","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/urllib-100-continue-loop.html","https://security.netapp.com/advisory/ntap-20220407-0009/","https://ubuntu.com/security/CVE-2021-3737","https://www.oracle.com/security-alerts/cpujul2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3737","description":"A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qjw2-hr98-qgfh","versionConstraint":">=2.7.0,<=2.9.10.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qjw2-hr98-qgfh","fix":{"state":"fixed","versions":["2.9.10.6"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-24750","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-24750","date":"2026-10-08","epss":0.07327,"percentile":0.94239}],"risk":5.71506,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-24750","https://github.com/FasterXML/jackson-databind/issues/2798","https://github.com/FasterXML/jackson-databind/commit/ad5a630174f08d279504bc51ebba8772fd71b86b","https://security.netapp.com/advisory/ntap-20201009-0003/","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://github.com/FasterXML/jackson-databind/commit/2118e71325486c68f089a9761c9d8a11b4ddd1cb","https://www.oracle.com/security-alerts/cpuapr2022.html","https://github.com/FasterXML/jackson-databind/commit/6cc9f1a1af323cd156f5668a47e43bab324ae16f"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qjw2-hr98-qgfh","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-24750","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-24750","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-24750","date":"2026-10-08","epss":0.07327,"percentile":0.94239}],"urls":["https://github.com/FasterXML/jackson-databind/commit/ad5a630174f08d279504bc51ebba8772fd71b86b","https://github.com/FasterXML/jackson-databind/issues/2798","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20201009-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-24750","description":"FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mx7p-6679-8g3q","versionConstraint":">=2.9.0,<2.9.10.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mx7p-6679-8g3q","fix":{"state":"fixed","versions":["2.9.10.1"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16942","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-16942","date":"2026-10-08","epss":0.05728,"percentile":0.9285}],"risk":5.38432,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-16942","https://github.com/FasterXML/jackson-databind/issues/2478","https://issues.apache.org/jira/browse/GEODE-7255","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/7782a937c9259a58337ee36b2961f00e2d744feafc13084e176d0df5@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/a430dbc9be874c41314cc69e697384567a9a24025e819d9485547954@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b2e23c94f9dfef53e04c492e5d02e5c75201734be7adc73a49ef2370@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://seclists.org/bugtraq/2019/Oct/6","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/328a0f833daf6baa443ac3b37c818a0204714b0b","https://github.com/FasterXML/jackson-databind/commit/54aa38d87dcffa5ccc23e64922e9536c82c1b9c8","https://github.com/FasterXML/jackson-databind/commit/9593e16cf5a3d289a9c584f7123639655de9ddac","https://github.com/FasterXML/jackson-databind/commit/bc67eb11a7cf57561f861ff16f879f1fceb5779f","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT","https://security.netapp.com/advisory/ntap-20191017-0006"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mx7p-6679-8g3q","description":"Polymorphic Typing in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-16942","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16942","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-16942","date":"2026-10-08","epss":0.05728,"percentile":0.9285}],"urls":["https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://github.com/FasterXML/jackson-databind/issues/2478","https://issues.apache.org/jira/browse/GEODE-7255","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/7782a937c9259a58337ee36b2961f00e2d744feafc13084e176d0df5%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/a430dbc9be874c41314cc69e697384567a9a24025e819d9485547954%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b2e23c94f9dfef53e04c492e5d02e5c75201734be7adc73a49ef2370%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16942","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling."}]},{"artifact":{"id":"71c53cb3237dc910","cpes":["cpe:2.3:a:libx11-6:libx11-6:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:libx11-6:libx11_6:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11-6:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11_6:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-6:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_6:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libx11-6","purl":"pkg:deb/ubuntu/libx11-6@2%3A1.6.4-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=libx11","type":"deb","version":"2:1.6.4-3ubuntu0.2","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libx11-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:1.6.4-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-31535","versionConstraint":"< 2:1.6.4-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libx11","version":"2:1.6.4-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-31535","fix":{"state":"fixed","versions":["2:1.6.4-3ubuntu0.4"],"available":[{"date":"2021-05-25","kind":"advisory","version":"2:1.6.4-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-31535","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31535","date":"2026-10-08","epss":0.10634,"percentile":0.95693}],"risk":5.317,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-31535"},"relatedVulnerabilities":[{"id":"CVE-2021-31535","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31535","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31535","date":"2026-10-08","epss":0.10634,"percentile":0.95693}],"urls":["http://packetstormsecurity.com/files/162737/libX11-Insufficient-Length-Check-Injection.html","http://seclists.org/fulldisclosure/2021/May/52","http://www.openwall.com/lists/oss-security/2021/05/18/2","https://gitlab.freedesktop.org/xorg/lib/libx11/-/commit/8d2e02ae650f00c4a53deb625211a0527126c605","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/05/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEOT4RLB76RVPJQKGGTIKTBIOLHX2NR6/","https://lists.freedesktop.org/archives/xorg/","https://lists.x.org/archives/xorg-announce/2021-May/003088.html","https://security.gentoo.org/glsa/202105-16","https://security.netapp.com/advisory/ntap-20210813-0001/","https://unparalleled.eu/blog/2021/20210518-using-xterm-to-navigate-the-huge-color-space/","https://unparalleled.eu/publications/2021/advisory-unpar-2021-1.txt","https://www.debian.org/security/2021/dsa-4920","https://www.openwall.com/lists/oss-security/2021/05/18/2","https://www.openwall.com/lists/oss-security/2021/05/18/3"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-31535","description":"LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the maximum size allowed by the protocol (and also longer than the maximum packet size for normal-sized packets). The user-controlled data exceeding the maximum size is then interpreted by the server as additional X protocol requests and executed, e.g., to disable X server authorization completely. For example, if the victim encounters malicious terminal control sequences for color codes, then the attacker may be able to take full control of the running graphical session."}]},{"artifact":{"id":"2f4014afda42ea84","cpes":["cpe:2.3:a:libx11-data:libx11-data:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:libx11-data:libx11_data:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11-data:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11_data:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-data:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_data:2\\:1.6.4-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libx11-data","purl":"pkg:deb/ubuntu/libx11-data@2%3A1.6.4-3ubuntu0.2?arch=all&distro=ubuntu-18.04&upstream=libx11","type":"deb","version":"2:1.6.4-3ubuntu0.2","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-data/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libx11-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libx11-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libx11-data.list"}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:1.6.4-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-31535","versionConstraint":"< 2:1.6.4-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libx11","version":"2:1.6.4-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-31535","fix":{"state":"fixed","versions":["2:1.6.4-3ubuntu0.4"],"available":[{"date":"2021-05-25","kind":"advisory","version":"2:1.6.4-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-31535","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31535","date":"2026-10-08","epss":0.10634,"percentile":0.95693}],"risk":5.317,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-31535"},"relatedVulnerabilities":[{"id":"CVE-2021-31535","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31535","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31535","date":"2026-10-08","epss":0.10634,"percentile":0.95693}],"urls":["http://packetstormsecurity.com/files/162737/libX11-Insufficient-Length-Check-Injection.html","http://seclists.org/fulldisclosure/2021/May/52","http://www.openwall.com/lists/oss-security/2021/05/18/2","https://gitlab.freedesktop.org/xorg/lib/libx11/-/commit/8d2e02ae650f00c4a53deb625211a0527126c605","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/05/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEOT4RLB76RVPJQKGGTIKTBIOLHX2NR6/","https://lists.freedesktop.org/archives/xorg/","https://lists.x.org/archives/xorg-announce/2021-May/003088.html","https://security.gentoo.org/glsa/202105-16","https://security.netapp.com/advisory/ntap-20210813-0001/","https://unparalleled.eu/blog/2021/20210518-using-xterm-to-navigate-the-huge-color-space/","https://unparalleled.eu/publications/2021/advisory-unpar-2021-1.txt","https://www.debian.org/security/2021/dsa-4920","https://www.openwall.com/lists/oss-security/2021/05/18/2","https://www.openwall.com/lists/oss-security/2021/05/18/3"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-31535","description":"LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the maximum size allowed by the protocol (and also longer than the maximum packet size for normal-sized packets). The user-controlled data exceeding the maximum size is then interpreted by the server as additional X protocol requests and executed, e.g., to disable X server authorization completely. For example, if the victim encounters malicious terminal control sequences for color codes, then the attacker may be able to take full control of the running graphical session."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-1971","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-1971","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.7"],"available":[{"date":"2020-12-08","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-1971","date":"2026-10-08","epss":0.07051,"percentile":0.94041}],"risk":5.28825,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1971"},"relatedVulnerabilities":[{"id":"CVE-2020-1971","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-1971","date":"2026-10-08","epss":0.07051,"percentile":0.94041}],"urls":["http://www.openwall.com/lists/oss-security/2021/09/14/2","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2154ab83e14ede338d2ede9bbe5cdfce5d5a6c9e","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f960d81215ebf3f65e03d4d5d857fb9b666d6920","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44676","https://lists.apache.org/thread.html/r63c6f2dd363d9b514d0a4bcf624580616a679898cc14c109a49b750c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rbb769f771711fb274e0a4acb1b5911c8aab544a6ac5e8c12d40c5143%40%3Ccommits.pulsar.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00020.html","https://lists.debian.org/debian-lts-announce/2020/12/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DGSI34Y5LQ5RYXN4M2I5ZQT65LFVDOUU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PWPSSZNZOBJU2YR6Z4TGHXKYW3YP5QG7/","https://security.FreeBSD.org/advisories/FreeBSD-SA-20:33.openssl.asc","https://security.gentoo.org/glsa/202012-13","https://security.netapp.com/advisory/ntap-20201218-0005/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2020/dsa-4807","https://www.openssl.org/news/secadv/20201208.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2020-11","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1971","description":"The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the \"-crl_download\" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-1971","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-1971","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.7"],"available":[{"date":"2020-12-08","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-1971","date":"2026-10-08","epss":0.07051,"percentile":0.94041}],"risk":5.28825,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-1971"},"relatedVulnerabilities":[{"id":"CVE-2020-1971","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-1971","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-1971","date":"2026-10-08","epss":0.07051,"percentile":0.94041}],"urls":["http://www.openwall.com/lists/oss-security/2021/09/14/2","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2154ab83e14ede338d2ede9bbe5cdfce5d5a6c9e","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f960d81215ebf3f65e03d4d5d857fb9b666d6920","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44676","https://lists.apache.org/thread.html/r63c6f2dd363d9b514d0a4bcf624580616a679898cc14c109a49b750c%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rbb769f771711fb274e0a4acb1b5911c8aab544a6ac5e8c12d40c5143%40%3Ccommits.pulsar.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00020.html","https://lists.debian.org/debian-lts-announce/2020/12/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DGSI34Y5LQ5RYXN4M2I5ZQT65LFVDOUU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PWPSSZNZOBJU2YR6Z4TGHXKYW3YP5QG7/","https://security.FreeBSD.org/advisories/FreeBSD-SA-20:33.openssl.asc","https://security.gentoo.org/glsa/202012-13","https://security.netapp.com/advisory/ntap-20201218-0005/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2020/dsa-4807","https://www.openssl.org/news/secadv/20201208.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2020-11","https://www.tenable.com/security/tns-2021-09","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1971","description":"The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the \"-crl_download\" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w)."}]},{"artifact":{"id":"100fe9e3e8e98cf6","cpes":["cpe:2.3:a:libonig4:libonig4:6.7.0-1:*:*:*:*:*:*:*"],"name":"libonig4","purl":"pkg:deb/ubuntu/libonig4@6.7.0-1?arch=amd64&distro=ubuntu-18.04&upstream=libonig","type":"deb","version":"6.7.0-1","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libonig4/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libonig4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libonig4:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libonig4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libonig"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19012","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libonig","version":"6.7.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19012","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-19012","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-19012","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19012","date":"2026-10-08","epss":0.10539,"percentile":0.95665}],"risk":5.2695,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19012"},"relatedVulnerabilities":[{"id":"CVE-2019-19012","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-19012","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-19012","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19012","date":"2026-10-08","epss":0.10539,"percentile":0.95665}],"urls":["https://github.com/kkos/oniguruma/issues/164","https://github.com/kkos/oniguruma/releases/tag/v6.9.4_rc2","https://github.com/tarantula-team/CVE-2019-19012","https://lists.debian.org/debian-lts-announce/2019/12/msg00002.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NO267PLHGYZSWX3XTRPKYBKD4J3YOU5V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3MBNW6Z4DOXSCNWGBLQ7OA3OGUJ44WL/","https://usn.ubuntu.com/4460-1/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19012","description":"An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression."}]},{"artifact":{"id":"97ba7d9059437784","cpes":["cpe:2.3:a:apache:commons-io:2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_io:2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:io:2.6:*:*:*:*:*:*:*"],"name":"commons-io","purl":"pkg:maven/commons-io/commons-io@2.6","type":"java-archive","version":"2.6","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"commons-io","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/commons-io-2.6.jar","manifestName":"","pomArtifactID":"commons-io","archiveDigests":[{"value":"815893df5f31da2ece4040fe0a12fd44b577afaf","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/commons-io-2.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gwrp-pvrq-jmwv","versionConstraint":"<2.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"commons-io:commons-io","version":"2.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gwrp-pvrq-jmwv","fix":{"state":"fixed","versions":["2.7"],"available":[{"date":"2021-04-27","kind":"first-observed","version":"2.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-29425","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-29425","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-29425","date":"2026-10-08","epss":0.10549,"percentile":0.95667}],"risk":5.16901,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-29425","https://issues.apache.org/jira/browse/IO-556","https://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31@%3Cdev.commons.apache.org%3E","https://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330@%3Cdev.commons.apache.org%3E","https://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34@%3Cdev.myfaces.apache.org%3E","https://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa@%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a@%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e@%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d@%3Cdev.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/08/msg00016.html","https://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b@%3Cissues.zookeeper.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://arxiv.org/pdf/2306.05534.pdf","https://github.com/jensdietrich/xshady-release/tree/main/CVE-2021-29425","https://security.netapp.com/advisory/ntap-20220210-0004"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gwrp-pvrq-jmwv","description":"Path Traversal and Improper Input Validation in Apache Commons IO"},"relatedVulnerabilities":[{"id":"CVE-2021-29425","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-29425","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2021-29425","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-29425","date":"2026-10-08","epss":0.10549,"percentile":0.95667}],"urls":["https://issues.apache.org/jira/browse/IO-556","https://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34%40%3Cdev.myfaces.apache.org%3E","https://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e%40%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2%40%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa%40%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31%40%3Cdev.commons.apache.org%3E","https://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a%40%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3E","https://lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330%40%3Cdev.commons.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/08/msg00016.html","https://security.netapp.com/advisory/ntap-20220210-0004/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-29425","description":"In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like \"//../foo\", or \"\\\\..\\foo\", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus \"limited\" path traversal), if the calling code would use the result to construct a path value."}]},{"artifact":{"id":"3445236446ec4939","cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"krb5-locales","purl":"pkg:deb/ubuntu/krb5-locales@1.16-2ubuntu0.1?arch=all&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-36222","versionConstraint":"< 1.16-2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-36222","fix":{"state":"fixed","versions":["1.16-2ubuntu0.4"],"available":[{"date":"2023-03-16","kind":"advisory","version":"1.16-2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"risk":5.138,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-36222"},"relatedVulnerabilities":[{"id":"CVE-2021-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"urls":["https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562","https://github.com/krb5/krb5/releases","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20211104-0007/","https://web.mit.edu/kerberos/advisories/","https://www.debian.org/security/2021/dsa-4944","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36222","description":"ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation."}]},{"artifact":{"id":"f3fc35a2cb3401bd","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/ubuntu/libgssapi-krb5-2@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-36222","versionConstraint":"< 1.16-2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-36222","fix":{"state":"fixed","versions":["1.16-2ubuntu0.4"],"available":[{"date":"2023-03-16","kind":"advisory","version":"1.16-2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"risk":5.138,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-36222"},"relatedVulnerabilities":[{"id":"CVE-2021-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"urls":["https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562","https://github.com/krb5/krb5/releases","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20211104-0007/","https://web.mit.edu/kerberos/advisories/","https://www.debian.org/security/2021/dsa-4944","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36222","description":"ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation."}]},{"artifact":{"id":"ce64c2275844a0e2","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/ubuntu/libk5crypto3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-36222","versionConstraint":"< 1.16-2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-36222","fix":{"state":"fixed","versions":["1.16-2ubuntu0.4"],"available":[{"date":"2023-03-16","kind":"advisory","version":"1.16-2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"risk":5.138,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-36222"},"relatedVulnerabilities":[{"id":"CVE-2021-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"urls":["https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562","https://github.com/krb5/krb5/releases","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20211104-0007/","https://web.mit.edu/kerberos/advisories/","https://www.debian.org/security/2021/dsa-4944","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36222","description":"ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation."}]},{"artifact":{"id":"a0e77fe46f00e692","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/ubuntu/libkrb5-3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-36222","versionConstraint":"< 1.16-2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-36222","fix":{"state":"fixed","versions":["1.16-2ubuntu0.4"],"available":[{"date":"2023-03-16","kind":"advisory","version":"1.16-2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"risk":5.138,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-36222"},"relatedVulnerabilities":[{"id":"CVE-2021-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"urls":["https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562","https://github.com/krb5/krb5/releases","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20211104-0007/","https://web.mit.edu/kerberos/advisories/","https://www.debian.org/security/2021/dsa-4944","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36222","description":"ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation."}]},{"artifact":{"id":"402827dd4cb6593f","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/ubuntu/libkrb5support0@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-36222","versionConstraint":"< 1.16-2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-36222","fix":{"state":"fixed","versions":["1.16-2ubuntu0.4"],"available":[{"date":"2023-03-16","kind":"advisory","version":"1.16-2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"risk":5.138,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-36222"},"relatedVulnerabilities":[{"id":"CVE-2021-36222","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36222","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36222","date":"2026-10-08","epss":0.10276,"percentile":0.95584}],"urls":["https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562","https://github.com/krb5/krb5/releases","https://security.netapp.com/advisory/ntap-20211022-0003/","https://security.netapp.com/advisory/ntap-20211104-0007/","https://web.mit.edu/kerberos/advisories/","https://www.debian.org/security/2021/dsa-4944","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36222","description":"ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9vvp-fxw6-jcxr","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9vvp-fxw6-jcxr","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11113","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11113","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11113","date":"2026-10-08","epss":0.06278,"percentile":0.93407}],"risk":5.116570000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11113","https://github.com/FasterXML/jackson-databind/issues/2670","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/e2ba12d5d60715d95105e3e790fc234cfb59893d","https://security.netapp.com/advisory/ntap-20200403-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9vvp-fxw6-jcxr","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-11113","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11113","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11113","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11113","date":"2026-10-08","epss":0.06278,"percentile":0.93407}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2670","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11113","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gjmw-vf9h-g25v","versionConstraint":">=2.9.0,<2.9.10.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gjmw-vf9h-g25v","fix":{"state":"fixed","versions":["2.9.10.1"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17531","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17531","date":"2026-10-08","epss":0.05373,"percentile":0.92451}],"risk":5.05062,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-17531","https://github.com/FasterXML/jackson-databind/issues/2498","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2019:4192","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/b3c90d38f99db546de60fea65f99a924d540fae2285f014b79606ca5@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","https://security.netapp.com/advisory/ntap-20191024-0005/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/b5a304a98590b6bb766134f9261e6566dcbbb6d0"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gjmw-vf9h-g25v","description":"jackson-databind polymorphic typing issue"},"relatedVulnerabilities":[{"id":"CVE-2019-17531","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17531","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17531","date":"2026-10-08","epss":0.05373,"percentile":0.92451}],"urls":["https://access.redhat.com/errata/RHSA-2019:4192","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://github.com/FasterXML/jackson-databind/issues/2498","https://lists.apache.org/thread.html/b3c90d38f99db546de60fea65f99a924d540fae2285f014b79606ca5%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20191024-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-17531","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload."}]},{"artifact":{"id":"9f3810d847c83662","cpes":["cpe:2.3:a:org.jsoup:jsoup:1.11.3:*:*:*:*:*:*:*","cpe:2.3:a:jsoup:jsoup:1.11.3:*:*:*:*:*:*:*"],"name":"jsoup","purl":"pkg:maven/org.jsoup/jsoup@1.11.3","type":"java-archive","version":"1.11.3","language":"java","licenses":["https://jsoup.org/license"],"metadata":{"pomGroupID":"org.jsoup","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jsoup-1.11.3.jar","manifestName":"","pomArtifactID":"jsoup","archiveDigests":[{"value":"36da09a8f68484523fa2aaa100399d612b247d67","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jsoup-1.11.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.14.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m72m-mhq2-9p6c","versionConstraint":"<1.14.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jsoup:jsoup","version":"1.11.3"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-m72m-mhq2-9p6c","fix":{"state":"fixed","versions":["1.14.2"],"available":[{"date":"2021-08-24","kind":"first-observed","version":"1.14.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-37714","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2021-37714","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2021-37714","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-37714","date":"2026-10-08","epss":0.06689,"percentile":0.93738}],"risk":5.01675,"urls":["https://github.com/jhy/jsoup/security/advisories/GHSA-m72m-mhq2-9p6c","https://nvd.nist.gov/vuln/detail/CVE-2021-37714","https://jsoup.org/news/release-1.14.1","https://jsoup.org/news/release-1.14.2","https://lists.apache.org/thread.html/r685c5235235ad0c26e86d0ee987fb802c9675de6081dbf0516464e0b@%3Cnotifications.james.apache.org%3E","https://lists.apache.org/thread.html/r97404676a5cf591988faedb887d64e278f522adcaa823d89ca69defe@%3Cnotifications.james.apache.org%3E","https://lists.apache.org/thread.html/rc3354080fc67fb50b45b3c2d12dc4ca2a3c1c78dad3d3ba012c038aa@%3Cnotifications.james.apache.org%3E","https://lists.apache.org/thread.html/r50e9c9466c592ca9d707a5dea549524d19e3287da08d8392f643960e@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r215009dbf7467a9f6506d0c0024cb36cad30071010e62c9352cfaaf0@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r377b93d79817ce649e9e68b3456e6f499747ef1643fa987b342e082e@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r3d71f18adb78e50f626dde689161ca63d3b7491bd9718fcddfaecba7@%3Cissues.maven.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2022.html","https://security.netapp.com/advisory/ntap-20220210-0022/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m72m-mhq2-9p6c","description":"Uncaught Exception in jsoup"},"relatedVulnerabilities":[{"id":"CVE-2021-37714","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-37714","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2021-37714","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2021-37714","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-37714","date":"2026-10-08","epss":0.06689,"percentile":0.93738}],"urls":["https://github.com/jhy/jsoup/security/advisories/GHSA-m72m-mhq2-9p6c","https://jsoup.org/news/release-1.14.1","https://jsoup.org/news/release-1.14.2","https://lists.apache.org/thread.html/r215009dbf7467a9f6506d0c0024cb36cad30071010e62c9352cfaaf0%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r377b93d79817ce649e9e68b3456e6f499747ef1643fa987b342e082e%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r3d71f18adb78e50f626dde689161ca63d3b7491bd9718fcddfaecba7%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r50e9c9466c592ca9d707a5dea549524d19e3287da08d8392f643960e%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r685c5235235ad0c26e86d0ee987fb802c9675de6081dbf0516464e0b%40%3Cnotifications.james.apache.org%3E","https://lists.apache.org/thread.html/r97404676a5cf591988faedb887d64e278f522adcaa823d89ca69defe%40%3Cnotifications.james.apache.org%3E","https://lists.apache.org/thread.html/rc3354080fc67fb50b45b3c2d12dc4ca2a3c1c78dad3d3ba012c038aa%40%3Cnotifications.james.apache.org%3E","https://security.netapp.com/advisory/ntap-20220210-0022/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-37714","description":"jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wh8g-3j2c-rqj5","versionConstraint":">=2.0.0,<=2.9.10.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wh8g-3j2c-rqj5","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35490","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-35490","date":"2026-10-08","epss":0.06285,"percentile":0.93415}],"risk":4.9023,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-35490","https://github.com/FasterXML/jackson-databind/issues/2986","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/41b8bdb5ccc1d8edb71acf1c8234da235a24249d","https://security.netapp.com/advisory/ntap-20210122-0005"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wh8g-3j2c-rqj5","description":"Serialization gadgets exploit in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-35490","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-35490","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-35490","date":"2026-10-08","epss":0.06285,"percentile":0.93415}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2986","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210122-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-35490","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-8285","versionConstraint":"< 7.58.0-2ubuntu3.12 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8285","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.12"],"available":[{"date":"2020-12-09","kind":"advisory","version":"7.58.0-2ubuntu3.12"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8285","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8285","date":"2026-10-08","epss":0.0977,"percentile":0.95425}],"risk":4.885,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8285"},"relatedVulnerabilities":[{"id":"CVE-2020-8285","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8285","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8285","date":"2026-10-08","epss":0.0977,"percentile":0.95425}],"urls":["http://seclists.org/fulldisclosure/2021/Apr/51","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2020-8285.html","https://github.com/curl/curl/issues/6255","https://hackerone.com/reports/1045844","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/","https://security.gentoo.org/glsa/202012-14","https://security.netapp.com/advisory/ntap-20210122-0007/","https://support.apple.com/kb/HT212325","https://support.apple.com/kb/HT212326","https://support.apple.com/kb/HT212327","https://www.debian.org/security/2021/dsa-4881","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8285","description":"curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.12"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-8285","versionConstraint":"< 7.58.0-2ubuntu3.12 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8285","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.12"],"available":[{"date":"2020-12-09","kind":"advisory","version":"7.58.0-2ubuntu3.12"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8285","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8285","date":"2026-10-08","epss":0.0977,"percentile":0.95425}],"risk":4.885,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8285"},"relatedVulnerabilities":[{"id":"CVE-2020-8285","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8285","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-8285","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8285","date":"2026-10-08","epss":0.0977,"percentile":0.95425}],"urls":["http://seclists.org/fulldisclosure/2021/Apr/51","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2020-8285.html","https://github.com/curl/curl/issues/6255","https://hackerone.com/reports/1045844","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/","https://security.gentoo.org/glsa/202012-14","https://security.netapp.com/advisory/ntap-20210122-0007/","https://support.apple.com/kb/HT212325","https://support.apple.com/kb/HT212326","https://support.apple.com/kb/HT212327","https://www.debian.org/security/2021/dsa-4881","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8285","description":"curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-85cw-hj65-qqv9","versionConstraint":">=2.9.0,<2.9.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-85cw-hj65-qqv9","fix":{"state":"fixed","versions":["2.9.10"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16335","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-16335","date":"2026-10-08","epss":0.04958,"percentile":0.91959}],"risk":4.66052,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-16335","https://github.com/FasterXML/jackson-databind/issues/2449","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://access.redhat.com/errata/RHSA-2020:0729","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb@%3Ccommits.hbase.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191004-0002/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/73c1c2cc76e6cdd7f3a5615cbe3207fe96e4d3db"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-85cw-hj65-qqv9","description":"Polymorphic Typing issue in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-16335","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16335","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-16335","date":"2026-10-08","epss":0.04958,"percentile":0.91959}],"urls":["https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://access.redhat.com/errata/RHSA-2020:0729","https://github.com/FasterXML/jackson-databind/issues/2449","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69%40%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0%40%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb%40%3Ccommits.hbase.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191004-0002/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16335","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fmmc-742q-jg75","versionConstraint":">=2.9.0,<2.9.10.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-fmmc-742q-jg75","fix":{"state":"fixed","versions":["2.9.10.1"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16943","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-16943","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16943","date":"2026-10-08","epss":0.04901,"percentile":0.9187}],"risk":4.606940000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-16943","https://github.com/FasterXML/jackson-databind/issues/2478","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/5ec8d8d485c2c8ac55ea425f4cd96596ef37312532712639712ebcdd@%3Ccommits.iceberg.apache.org%3E","https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/328a0f833daf6baa443ac3b37c818a0204714b0b","https://github.com/FasterXML/jackson-databind/commit/bc67eb11a7cf57561f861ff16f879f1fceb5779f"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fmmc-742q-jg75","description":"jackson-databind polymorphic typing issue"},"relatedVulnerabilities":[{"id":"CVE-2019-16943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16943","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-16943","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-16943","date":"2026-10-08","epss":0.04901,"percentile":0.9187}],"urls":["https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://github.com/FasterXML/jackson-databind/issues/2478","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/5ec8d8d485c2c8ac55ea425f4cd96596ef37312532712639712ebcdd%40%3Ccommits.iceberg.apache.org%3E","https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6%40%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16943","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qxf4-chvg-4r8r","versionConstraint":">=9.0.0,<9.0.31 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qxf4-chvg-4r8r","fix":{"state":"fixed","versions":["9.0.31"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"9.0.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1935","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1935","date":"2026-10-08","epss":0.09386,"percentile":0.95286}],"risk":4.59914,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-1935","https://lists.apache.org/thread.html/r127f76181aceffea2bd4711b03c595d0f115f63e020348fe925a916c%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743@%3Ccommits.tomee.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://security.netapp.com/advisory/ntap-20200327-0005/","https://www.debian.org/security/2020/dsa-4673","https://www.debian.org/security/2020/dsa-4680","https://lists.apache.org/thread.html/r441c1f30a252bf14b07396286f6abd8089ce4240e91323211f1a2d75@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r660cd379afe346f10d72c0eaa8459ccc95d83aff181671b7e9076919@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/ra5dee390ad2d60307b8362505c059cd6a726de4d146d63dfce1e05e7@%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd547be0c9d821b4b1000a694b8e58ef9f5e2d66db03a31dfe77c4b18@%3Cusers.tomcat.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r80e9c8417c77d52c62809168b96912bda70ddf7748f19f8210f745b1@%3Cusers.tomcat.apache.org%3E","https://usn.ubuntu.com/4448-1/","https://lists.apache.org/thread.html/r9ce7918faf347e7aac32be930bf26c233b0b140fe37af0bb294158b6@%3Cdev.tomcat.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qxf4-chvg-4r8r","description":"Potential HTTP request smuggling in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2020-1935","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-1935","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-1935","date":"2026-10-08","epss":0.09386,"percentile":0.95286}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","https://lists.apache.org/thread.html/r127f76181aceffea2bd4711b03c595d0f115f63e020348fe925a916c%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r441c1f30a252bf14b07396286f6abd8089ce4240e91323211f1a2d75%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r660cd379afe346f10d72c0eaa8459ccc95d83aff181671b7e9076919%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r80e9c8417c77d52c62809168b96912bda70ddf7748f19f8210f745b1%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r9ce7918faf347e7aac32be930bf26c233b0b140fe37af0bb294158b6%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/ra5dee390ad2d60307b8362505c059cd6a726de4d146d63dfce1e05e7%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rd547be0c9d821b4b1000a694b8e58ef9f5e2d66db03a31dfe77c4b18%40%3Cusers.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://security.netapp.com/advisory/ntap-20200327-0005/","https://usn.ubuntu.com/4448-1/","https://www.debian.org/security/2020/dsa-4673","https://www.debian.org/security/2020/dsa-4680","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-1935","description":"In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h4rc-386g-6m85","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h4rc-386g-6m85","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11620","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11620","date":"2026-10-08","epss":0.0578,"percentile":0.92904}],"risk":4.5084,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11620","https://github.com/FasterXML/jackson-databind/issues/2682","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/77040d85e3eb6710508e6445640ae1a3d5e60c22","https://security.netapp.com/advisory/ntap-20200511-0004"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h4rc-386g-6m85","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-11620","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11620","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11620","date":"2026-10-08","epss":0.0578,"percentile":0.92904}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2682","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200511-0004/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11620","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly)."}]},{"artifact":{"id":"8e62788fd0d03826","cpes":["cpe:2.3:a:org.springframework.security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:security:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-security-core","purl":"pkg:maven/org.springframework.security/spring-security-core@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.security","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-core-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-security-core","archiveDigests":[{"value":"1c8f36e316a74c245073ce2a70bdf198a58424f6","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-core-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w9jg-gvgr-354m","versionConstraint":">=5.2.0,<=5.2.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.security:spring-security-core","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-w9jg-gvgr-354m","fix":{"state":"fixed","versions":["5.2.11"],"available":[{"date":"2021-07-03","kind":"first-observed","version":"5.2.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22119","cwe":"CWE-400","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2021-22119","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22119","date":"2026-10-08","epss":0.06001,"percentile":0.93144}],"risk":4.50075,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-22119","https://github.com/spring-projects/spring-security/pull/9513","https://tanzu.vmware.com/security/cve-2021-22119","https://lists.apache.org/thread.html/r163b3e4e39803882f5be05ee8606b2b9812920e196daa2a82997ce14@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r3868207b967f926819fe3aa8d33f1666429be589bb4a62104a49f4e3@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r390783b3b1c59b978131ac08390bf77fbb3863270cbde59d5b0f5fde@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r89aa1b48a827f5641310305214547f1d6b2101971a49b624737c497f@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/ra53677224fe4f04c2599abc88032076faa18dc84b329cdeba85d4cfc@%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/r08a449010786e0bcffa4b5781b04fcb55d6eafa62cb79b8347680aad@%3Cissues.nifi.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w9jg-gvgr-354m","description":"Resource Exhaustion in Spring Security"},"relatedVulnerabilities":[{"id":"CVE-2021-22119","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22119","cwe":"CWE-400","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2021-22119","cwe":"CWE-863","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22119","date":"2026-10-08","epss":0.06001,"percentile":0.93144}],"urls":["https://lists.apache.org/thread.html/r08a449010786e0bcffa4b5781b04fcb55d6eafa62cb79b8347680aad%40%3Cissues.nifi.apache.org%3E","https://lists.apache.org/thread.html/r163b3e4e39803882f5be05ee8606b2b9812920e196daa2a82997ce14%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r3868207b967f926819fe3aa8d33f1666429be589bb4a62104a49f4e3%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r390783b3b1c59b978131ac08390bf77fbb3863270cbde59d5b0f5fde%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r89aa1b48a827f5641310305214547f1d6b2101971a49b624737c497f%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/ra53677224fe4f04c2599abc88032076faa18dc84b329cdeba85d4cfc%40%3Cpluto-scm.portals.apache.org%3E","https://tanzu.vmware.com/security/cve-2021-22119","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22119","description":"Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client Web and WebFlux application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session or multiple sessions."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f3j5-rmmp-3fc5","versionConstraint":">=2.9.0,<2.9.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-f3j5-rmmp-3fc5","fix":{"state":"fixed","versions":["2.9.10"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17267","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-17267","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-17267","date":"2026-10-08","epss":0.04628,"percentile":0.91467}],"risk":4.350320000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-17267","https://github.com/FasterXML/jackson-databind/issues/2460","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3...jackson-databind-2.9.10","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r9d727fc681fb3828794acbefcaee31393742b4d73a29461ccd9597a8@%3Cdev.skywalking.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/191a4cdf87b56d2ddddb77edd895ee756b7f75eb"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f3j5-rmmp-3fc5","description":"Improper Input Validation in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-17267","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17267","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-17267","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-17267","date":"2026-10-08","epss":0.04628,"percentile":0.91467}],"urls":["https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3...jackson-databind-2.9.10","https://github.com/FasterXML/jackson-databind/issues/2460","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r9d727fc681fb3828794acbefcaee31393742b4d73a29461ccd9597a8%40%3Cdev.skywalking.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-17267","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5p34-5m6p-p58g","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5p34-5m6p-p58g","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9546","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9546","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9546","date":"2026-10-08","epss":0.04613,"percentile":0.91443}],"risk":4.33622,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-9546","https://github.com/FasterXML/jackson-databind/issues/2631","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://security.netapp.com/advisory/ntap-20200904-0006","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd%40%3Cissues.zookeeper.apache.org%3E"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5p34-5m6p-p58g","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-9546","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-9546","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-9546","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-9546","date":"2026-10-08","epss":0.04613,"percentile":0.91443}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2631","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18%40%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1%40%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097%40%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-9546","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config)."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1551","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1551","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.6"],"available":[{"date":"2020-05-28","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1551","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1551","date":"2026-10-08","epss":0.14298,"percentile":0.96523}],"risk":4.2894,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1551"},"relatedVulnerabilities":[{"id":"CVE-2019-1551","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1551","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1551","date":"2026-10-08","epss":0.14298,"percentile":0.96523}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00030.html","http://packetstormsecurity.com/files/155754/Slackware-Security-Advisory-openssl-Updates.html","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=419102400a2811582a7a3d4a4e317d72e5ce0a8f","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f1c5eea8a817075d31e43f5876993c6710238c98","https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/","https://seclists.org/bugtraq/2019/Dec/39","https://seclists.org/bugtraq/2019/Dec/46","https://security.gentoo.org/glsa/202004-10","https://security.netapp.com/advisory/ntap-20191210-0001/","https://usn.ubuntu.com/4376-1/","https://usn.ubuntu.com/4504-1/","https://www.debian.org/security/2019/dsa-4594","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20191206.txt","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.tenable.com/security/tns-2019-09","https://www.tenable.com/security/tns-2020-03","https://www.tenable.com/security/tns-2020-11","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1551","description":"There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-1551","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1551","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.6"],"available":[{"date":"2020-05-28","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1551","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1551","date":"2026-10-08","epss":0.14298,"percentile":0.96523}],"risk":4.2894,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1551"},"relatedVulnerabilities":[{"id":"CVE-2019-1551","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1551","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1551","date":"2026-10-08","epss":0.14298,"percentile":0.96523}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00030.html","http://packetstormsecurity.com/files/155754/Slackware-Security-Advisory-openssl-Updates.html","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=419102400a2811582a7a3d4a4e317d72e5ce0a8f","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f1c5eea8a817075d31e43f5876993c6710238c98","https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/","https://seclists.org/bugtraq/2019/Dec/39","https://seclists.org/bugtraq/2019/Dec/46","https://security.gentoo.org/glsa/202004-10","https://security.netapp.com/advisory/ntap-20191210-0001/","https://usn.ubuntu.com/4376-1/","https://usn.ubuntu.com/4504-1/","https://www.debian.org/security/2019/dsa-4594","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20191206.txt","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.tenable.com/security/tns-2019-09","https://www.tenable.com/security/tns-2020-03","https://www.tenable.com/security/tns-2020-11","https://www.tenable.com/security/tns-2021-10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1551","description":"There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t)."}]},{"artifact":{"id":"d6ef7367e3013e37","cpes":["cpe:2.3:a:org.springframework:spring-context:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_context:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-context:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_context:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-context:spring-context:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-context:spring_context:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_context:spring-context:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_context:spring_context:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-context:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_context:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-context","purl":"pkg:maven/org.springframework/spring-context@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-context-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-context","archiveDigests":[{"value":"a2638a8295f13ed8511c98a2379507677e1d16fa","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-context-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.21.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g5mm-vmx4-3rg7","versionConstraint":"<5.2.21.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-context","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-g5mm-vmx4-3rg7","fix":{"state":"fixed","versions":["5.2.21.RELEASE"],"available":[{"date":"2024-05-16","kind":"first-observed","version":"5.2.21.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22968","cwe":"CWE-178","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22968","date":"2026-10-08","epss":0.05666,"percentile":0.92782}],"risk":4.2495,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22968","https://tanzu.vmware.com/security/cve-2022-22968","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/spring-projects/spring-framework/commit/833e750175349ab4fd502109a8b41af77e25cdea","https://github.com/spring-projects/spring-framework/commit/a7cf19cec5ebd270f97a194d749e2d5701ad2ab7","https://security.netapp.com/advisory/ntap-20220602-0004"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g5mm-vmx4-3rg7","description":"Improper handling of case sensitivity in Spring Framework"},"relatedVulnerabilities":[{"id":"CVE-2022-22968","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22968","cwe":"CWE-178","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22968","date":"2026-10-08","epss":0.05666,"percentile":0.92782}],"urls":["https://security.netapp.com/advisory/ntap-20220602-0004/","https://tanzu.vmware.com/security/cve-2022-22968","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22968","description":"In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35556","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35556","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-35556","cwe":"CWE-693","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35556","date":"2026-10-08","epss":0.08464,"percentile":0.94888}],"risk":4.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35556"},"relatedVulnerabilities":[{"id":"CVE-2021-35556","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-35556","cwe":"CWE-693","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-35556","date":"2026-10-08","epss":0.08464,"percentile":0.94888}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35556","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cf6r-3wgc-h863","versionConstraint":">=2.9.0,<2.9.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cf6r-3wgc-h863","fix":{"state":"fixed","versions":["2.9.10"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14892","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14892","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14892","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14892","date":"2026-10-08","epss":0.05622,"percentile":0.92743}],"risk":4.2165,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-14892","https://github.com/FasterXML/jackson-databind/issues/2462","https://github.com/FasterXML/jackson-databind/commit/41b7f9b90149e9d44a65a8261a8deedc7186f6af","https://github.com/FasterXML/jackson-databind/commit/819cdbcab51c6da9fb896380f2d46e9b7d4fdc3b","https://access.redhat.com/errata/RHSA-2020:0729","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14892","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://security.netapp.com/advisory/ntap-20200904-0005/"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cf6r-3wgc-h863","description":"Polymorphic deserialization of malicious object in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-14892","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14892","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14892","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14892","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14892","date":"2026-10-08","epss":0.05622,"percentile":0.92743}],"urls":["https://access.redhat.com/errata/RHSA-2020:0729","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14892","https://github.com/FasterXML/jackson-databind/issues/2462","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://security.netapp.com/advisory/ntap-20200904-0005/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14892","description":"A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21293","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21293","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21293","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21293","date":"2026-10-08","epss":0.08346,"percentile":0.94825}],"risk":4.173,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21293"},"relatedVulnerabilities":[{"id":"CVE-2022-21293","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21293","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21293","date":"2026-10-08","epss":0.08346,"percentile":0.94825}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2DIN3L6L3SVZK75CKW2GPSU4HIGZR7XG/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21293","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0391","versionConstraint":"< 3.6.9-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0391","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"risk":4.1625000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0391"},"relatedVulnerabilities":[{"id":"CVE-2022-0391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"urls":["https://bugs.python.org/issue43882","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20220225-0009/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0391","versionConstraint":"< 3.6.9-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0391","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"risk":4.1625000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0391"},"relatedVulnerabilities":[{"id":"CVE-2022-0391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"urls":["https://bugs.python.org/issue43882","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20220225-0009/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-0391","versionConstraint":"< 3.6.9-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0391","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"risk":4.1625000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0391"},"relatedVulnerabilities":[{"id":"CVE-2022-0391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"urls":["https://bugs.python.org/issue43882","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20220225-0009/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0391","versionConstraint":"< 3.6.9-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0391","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"risk":4.1625000000000005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0391"},"relatedVulnerabilities":[{"id":"CVE-2022-0391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"urls":["https://bugs.python.org/issue43882","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20220225-0009/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9m6f-7xcq-8vf8","versionConstraint":">=2.7.00,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9m6f-7xcq-8vf8","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36183","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36183","date":"2026-10-08","epss":0.04972,"percentile":0.91979}],"risk":3.87816,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36183","https://github.com/FasterXML/jackson-databind/issues/3003","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/12e23c962ffb4cf1857c5461d72ae54cc8008f29","https://security.netapp.com/advisory/ntap-20210205-0005"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9m6f-7xcq-8vf8","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36183","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36183","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36183","date":"2026-10-08","epss":0.04972,"percentile":0.91979}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/3003","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36183","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21340","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21340","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21340","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21340","date":"2026-10-08","epss":0.07748,"percentile":0.9449}],"risk":3.8739999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21340"},"relatedVulnerabilities":[{"id":"CVE-2022-21340","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21340","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21340","date":"2026-10-08","epss":0.07748,"percentile":0.9449}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21340","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14422","versionConstraint":"< 3.6.9-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14422","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-14422","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14422","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14422","date":"2026-10-08","epss":0.12706,"percentile":0.96173}],"risk":3.8118,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14422"},"relatedVulnerabilities":[{"id":"CVE-2020-14422","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14422","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14422","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14422","date":"2026-10-08","epss":0.12706,"percentile":0.96173}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00003.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00006.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00032.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00041.html","https://bugs.python.org/issue41004","https://github.com/python/cpython/pull/20956","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00016.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCCZTAYZATTNSNEAXWA7U3HCO2OVQKT5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X36Y523UAZY5QFXZAAORNFY63HLBWX7N/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200724-0004/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14422","description":"Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14422","versionConstraint":"< 3.6.9-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14422","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-14422","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14422","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14422","date":"2026-10-08","epss":0.12706,"percentile":0.96173}],"risk":3.8118,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14422"},"relatedVulnerabilities":[{"id":"CVE-2020-14422","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14422","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14422","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14422","date":"2026-10-08","epss":0.12706,"percentile":0.96173}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00003.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00006.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00032.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00041.html","https://bugs.python.org/issue41004","https://github.com/python/cpython/pull/20956","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00016.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCCZTAYZATTNSNEAXWA7U3HCO2OVQKT5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X36Y523UAZY5QFXZAAORNFY63HLBWX7N/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200724-0004/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14422","description":"Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-14422","versionConstraint":"< 3.6.9-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14422","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-14422","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14422","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14422","date":"2026-10-08","epss":0.12706,"percentile":0.96173}],"risk":3.8118,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14422"},"relatedVulnerabilities":[{"id":"CVE-2020-14422","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14422","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14422","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14422","date":"2026-10-08","epss":0.12706,"percentile":0.96173}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00003.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00006.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00032.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00041.html","https://bugs.python.org/issue41004","https://github.com/python/cpython/pull/20956","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00016.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCCZTAYZATTNSNEAXWA7U3HCO2OVQKT5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X36Y523UAZY5QFXZAAORNFY63HLBWX7N/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200724-0004/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14422","description":"Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14422","versionConstraint":"< 3.6.9-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14422","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-14422","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14422","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14422","date":"2026-10-08","epss":0.12706,"percentile":0.96173}],"risk":3.8118,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14422"},"relatedVulnerabilities":[{"id":"CVE-2020-14422","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14422","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14422","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14422","date":"2026-10-08","epss":0.12706,"percentile":0.96173}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00003.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00006.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00032.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00041.html","https://bugs.python.org/issue41004","https://github.com/python/cpython/pull/20956","https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00016.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCCZTAYZATTNSNEAXWA7U3HCO2OVQKT5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X36Y523UAZY5QFXZAAORNFY63HLBWX7N/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200724-0004/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14422","description":"Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2."}]},{"artifact":{"id":"a9cc0a7ecffa316e","cpes":["cpe:2.3:a:thymeleaf-spring5:thymeleaf-spring5:3.0.11.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf-spring5:thymeleaf_spring5:3.0.11.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf_spring5:thymeleaf-spring5:3.0.11.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf_spring5:thymeleaf_spring5:3.0.11.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf-team:thymeleaf-spring5:3.0.11.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf-team:thymeleaf_spring5:3.0.11.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf_team:thymeleaf-spring5:3.0.11.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf_team:thymeleaf_spring5:3.0.11.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.thymeleaf:thymeleaf-spring5:3.0.11.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.thymeleaf:thymeleaf_spring5:3.0.11.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf:thymeleaf-spring5:3.0.11.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:thymeleaf:thymeleaf_spring5:3.0.11.RELEASE:*:*:*:*:*:*:*"],"name":"thymeleaf-spring5","purl":"pkg:maven/org.thymeleaf/thymeleaf-spring5@3.0.11.RELEASE","type":"java-archive","version":"3.0.11.RELEASE","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.thymeleaf","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/thymeleaf-spring5-3.0.11.RELEASE.jar","manifestName":"","pomArtifactID":"thymeleaf-spring5","archiveDigests":[{"value":"de7bf0adf13b5e9c4811f95edf18279da193c0c6","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/thymeleaf-spring5-3.0.11.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qcj6-jqrg-4wp2","versionConstraint":"<=3.0.12.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.thymeleaf:thymeleaf-spring5","version":"3.0.11.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qcj6-jqrg-4wp2","fix":{"state":"fixed","versions":["3.0.13.RELEASE"],"available":[{"date":"2022-03-15","kind":"first-observed","version":"3.0.13.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-43466","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-43466","date":"2026-10-08","epss":0.03993,"percentile":0.90254}],"risk":3.75342,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-43466","https://vuldb.com/?id.186365","https://github.com/thymeleaf/thymeleaf-spring/issues/263#issuecomment-977199524","https://gitee.com/wayne_wwang/wayne_wwang/blob/master/2021/10/31/ruoyi+thymeleaf-rce/index.html","https://security.netapp.com/advisory/ntap-20221014-0001/"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qcj6-jqrg-4wp2","description":"Template injection in thymeleaf-spring5"},"relatedVulnerabilities":[{"id":"CVE-2021-43466","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-43466","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-43466","date":"2026-10-08","epss":0.03993,"percentile":0.90254}],"urls":["https://gitee.com/wayne_wwang/wayne_wwang/blob/master/2021/10/31/ruoyi+thymeleaf-rce/index.html","https://security.netapp.com/advisory/ntap-20221014-0001/","https://vuldb.com/?id.186365"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-43466","description":"In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.19"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-32208","versionConstraint":"< 7.58.0-2ubuntu3.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32208","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.19"],"available":[{"date":"2022-06-27","kind":"advisory","version":"7.58.0-2ubuntu3.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32208","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32208","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32208","date":"2026-10-08","epss":0.07499,"percentile":0.94338}],"risk":3.7495000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32208"},"relatedVulnerabilities":[{"id":"CVE-2022-32208","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32208","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32208","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32208","date":"2026-10-08","epss":0.07499,"percentile":0.94338}],"urls":["http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","https://hackerone.com/reports/1590071","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220915-0003/","https://support.apple.com/kb/HT213488","https://www.debian.org/security/2022/dsa-5197"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32208","description":"When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.19"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-32208","versionConstraint":"< 7.58.0-2ubuntu3.19 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32208","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.19"],"available":[{"date":"2022-06-27","kind":"advisory","version":"7.58.0-2ubuntu3.19"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32208","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32208","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32208","date":"2026-10-08","epss":0.07499,"percentile":0.94338}],"risk":3.7495000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32208"},"relatedVulnerabilities":[{"id":"CVE-2022-32208","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32208","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32208","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32208","date":"2026-10-08","epss":0.07499,"percentile":0.94338}],"urls":["http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","https://hackerone.com/reports/1590071","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220915-0003/","https://support.apple.com/kb/HT213488","https://www.debian.org/security/2022/dsa-5197"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32208","description":"When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-25235","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-25235","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-25235","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25235","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25235","date":"2026-10-08","epss":0.04955,"percentile":0.91956}],"risk":3.71625,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-25235"},"relatedVulnerabilities":[{"id":"CVE-2022-25235","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25235","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25235","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25235","date":"2026-10-08","epss":0.04955,"percentile":0.91956}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/19/1","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/562","https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220303-0008/","https://www.debian.org/security/2022/dsa-5085","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25235","description":"xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-23841","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23841","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.8"],"available":[{"date":"2021-02-18","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-23841","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-23841","date":"2026-10-08","epss":0.0741,"percentile":0.94291}],"risk":3.705,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23841"},"relatedVulnerabilities":[{"id":"CVE-2021-23841","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23841","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-23841","date":"2026-10-08","epss":0.0741,"percentile":0.94291}],"urls":["http://seclists.org/fulldisclosure/2021/May/67","http://seclists.org/fulldisclosure/2021/May/68","http://seclists.org/fulldisclosure/2021/May/70","https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=122a19ab48091c657f7cb1fb3af9fc07bd557bbf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8252ee4d90f3f2004d3d0aeeed003ad49c9a7807","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210219-0009/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://support.apple.com/kb/HT212528","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212534","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20210216.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-03","https://www.tenable.com/security/tns-2021-09"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23841","description":"The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-23841","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-23841","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.8"],"available":[{"date":"2021-02-18","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-23841","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-23841","date":"2026-10-08","epss":0.0741,"percentile":0.94291}],"risk":3.705,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-23841"},"relatedVulnerabilities":[{"id":"CVE-2021-23841","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23841","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-23841","date":"2026-10-08","epss":0.0741,"percentile":0.94291}],"urls":["http://seclists.org/fulldisclosure/2021/May/67","http://seclists.org/fulldisclosure/2021/May/68","http://seclists.org/fulldisclosure/2021/May/70","https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=122a19ab48091c657f7cb1fb3af9fc07bd557bbf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8252ee4d90f3f2004d3d0aeeed003ad49c9a7807","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846","https://security.gentoo.org/glsa/202103-03","https://security.netapp.com/advisory/ntap-20210219-0009/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://support.apple.com/kb/HT212528","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212534","https://www.debian.org/security/2021/dsa-4855","https://www.openssl.org/news/secadv/20210216.txt","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.tenable.com/security/tns-2021-03","https://www.tenable.com/security/tns-2021-09"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23841","description":"The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35565","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35565","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35565","date":"2026-10-08","epss":0.07395,"percentile":0.94281}],"risk":3.6975000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35565"},"relatedVulnerabilities":[{"id":"CVE-2021-35565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35565","date":"2026-10-08","epss":0.07395,"percentile":0.94281}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35565","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35550","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35550","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35550","date":"2026-10-08","epss":0.07376,"percentile":0.94269}],"risk":3.688,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35550"},"relatedVulnerabilities":[{"id":"CVE-2021-35550","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:N/A:N","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35550","date":"2026-10-08","epss":0.07376,"percentile":0.94269}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35550","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.12.6.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-57j2-w4cx-62h2","versionConstraint":"<=2.12.6.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-57j2-w4cx-62h2","fix":{"state":"fixed","versions":["2.12.6.1"],"available":[{"date":"2022-03-29","kind":"first-observed","version":"2.12.6.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36518","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36518","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36518","date":"2026-10-08","epss":0.0486,"percentile":0.91812}],"risk":3.6449999999999996,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36518","https://github.com/FasterXML/jackson-databind/issues/2816","https://github.com/FasterXML/jackson-databind/commit/fcfc4998ec23f0b1f7f8a9521c2b317b6c25892b","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.12","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.13","https://lists.debian.org/debian-lts-announce/2022/05/msg00001.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://www.debian.org/security/2022/dsa-5283","https://github.com/FasterXML/jackson-databind/commit/0a8157c6ca478b1bc7be4ba7dccdb3863275f0de","https://github.com/FasterXML/jackson-databind/commit/3cc52f82ecf943e06c1d7c3b078e405fb3923d2b","https://github.com/FasterXML/jackson-databind/commit/8238ab41d0350fb915797c89d46777b4496b74fd","https://github.com/FasterXML/jackson-databind/commit/b3587924ee5d8695942f364d0d404d48d0ea6126","https://security.netapp.com/advisory/ntap-20220506-0004"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-57j2-w4cx-62h2","description":"Deeply nested json in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36518","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36518","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36518","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36518","date":"2026-10-08","epss":0.0486,"percentile":0.91812}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2816","https://lists.debian.org/debian-lts-announce/2022/05/msg00001.html","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://security.netapp.com/advisory/ntap-20220506-0004/","https://www.debian.org/security/2022/dsa-5283","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36518","description":"jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.90"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wm9w-rjj3-j356","versionConstraint":">=9.0.0-M1,<9.0.90 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wm9w-rjj3-j356","fix":{"state":"fixed","versions":["9.0.90"],"available":[{"date":"2024-07-06","kind":"first-observed","version":"9.0.90"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34750","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2024-34750","cwe":"CWE-755","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-34750","date":"2026-10-08","epss":0.04602,"percentile":0.91424}],"risk":3.58956,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-34750","https://lists.apache.org/thread/4kqf0bc9gxymjc2x7v3p7dvplnl77y8l","https://github.com/apache/tomcat/commit/2344a4c0d03e307ba6b8ab6dc8b894cc8bac63f2","https://github.com/apache/tomcat/commit/2afae300c9ac9c0e516e2e9de580847d925365c3","https://github.com/apache/tomcat/commit/9fec9a82887853402833a80b584e3762c7423f5f","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-9.html","https://security.netapp.com/advisory/ntap-20240816-0004","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wm9w-rjj3-j356","description":"Apache Tomcat - Denial of Service"},"relatedVulnerabilities":[{"id":"CVE-2024-34750","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34750","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2024-34750","cwe":"CWE-755","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-34750","date":"2026-10-08","epss":0.04602,"percentile":0.91424}],"urls":["https://lists.apache.org/thread/4kqf0bc9gxymjc2x7v3p7dvplnl77y8l","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html","https://security.netapp.com/advisory/ntap-20240816-0004/","https://github.com/apache/tomcat/commit/2344a4c0d03e307ba6b8ab6dc8b894cc8bac63f2","https://github.com/apache/tomcat/commit/2afae300c9ac9c0e516e2e9de580847d925365c3","https://github.com/apache/tomcat/commit/9fec9a82887853402833a80b584e3762c7423f5f"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-34750","description":"Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89.\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mc6h-4qgp-37qh","versionConstraint":">=2.9.0,<=2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mc6h-4qgp-37qh","fix":{"state":"fixed","versions":["2.9.10.5"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14195","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14195","date":"2026-10-08","epss":0.04549,"percentile":0.91338}],"risk":3.5482200000000006,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-14195","https://github.com/FasterXML/jackson-databind/issues/2765","https://github.com/FasterXML/jackson-databind/commit/f6d9c664f6d481703138319f6a0f1fdbddb3a259","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://security.netapp.com/advisory/ntap-20200702-0003"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mc6h-4qgp-37qh","description":"Deserialization of untrusted data in Jackson Databind"},"relatedVulnerabilities":[{"id":"CVE-2020-14195","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14195","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-14195","date":"2026-10-08","epss":0.04549,"percentile":0.91338}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2765","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://security.netapp.com/advisory/ntap-20200702-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14195","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity)."}]},{"artifact":{"id":"685ff832fa5df143","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11236","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-11236","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"risk":3.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11236"},"relatedVulnerabilities":[{"id":"CVE-2018-11236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"urls":["http://www.securityfocus.com/bid/104255","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22786","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5460617d1567657621107d895ee2dd83bc1f88f2","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11236","description":"stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution."}]},{"artifact":{"id":"71315b6fa75a7166","cpes":["cpe:2.3:a:libc6:libc6:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11236","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-11236","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"risk":3.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11236"},"relatedVulnerabilities":[{"id":"CVE-2018-11236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"urls":["http://www.securityfocus.com/bid/104255","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22786","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5460617d1567657621107d895ee2dd83bc1f88f2","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11236","description":"stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution."}]},{"artifact":{"id":"62a0389fd254614a","cpes":["cpe:2.3:a:locales:locales:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.27-3ubuntu1?arch=all&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11236","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-11236","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"risk":3.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11236"},"relatedVulnerabilities":[{"id":"CVE-2018-11236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"urls":["http://www.securityfocus.com/bid/104255","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22786","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5460617d1567657621107d895ee2dd83bc1f88f2","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11236","description":"stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution."}]},{"artifact":{"id":"6c475aa8af85f1cd","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-11236","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-11236","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"risk":3.5255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-11236"},"relatedVulnerabilities":[{"id":"CVE-2018-11236","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-11236","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-11236","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-11236","date":"2026-10-08","epss":0.07051,"percentile":0.9404}],"urls":["http://www.securityfocus.com/bid/104255","https://access.redhat.com/errata/RHBA-2019:0327","https://access.redhat.com/errata/RHSA-2018:3092","https://security.netapp.com/advisory/ntap-20190329-0001/","https://security.netapp.com/advisory/ntap-20190401-0001/","https://sourceware.org/bugzilla/show_bug.cgi?id=22786","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=5460617d1567657621107d895ee2dd83bc1f88f2","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-11236","description":"stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c2q3-4qrh-fm48","versionConstraint":">=2.9.0,<=2.9.10.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c2q3-4qrh-fm48","fix":{"state":"fixed","versions":["2.9.10.5"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14061","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14061","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-14061","date":"2026-10-08","epss":0.04458,"percentile":0.91186}],"risk":3.47724,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-14061","https://github.com/FasterXML/jackson-databind/issues/2698","https://github.com/FasterXML/jackson-databind/commit/5c8642aeae9c756b438ab7637c90ef3c77966e6e","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://security.netapp.com/advisory/ntap-20200702-0003/","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c2q3-4qrh-fm48","description":"Deserialization of untrusted data in Jackson Databind"},"relatedVulnerabilities":[{"id":"CVE-2020-14061","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14061","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14061","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-14061","date":"2026-10-08","epss":0.04458,"percentile":0.91186}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2698","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200702-0003/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14061","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35561","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35561","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35561","date":"2026-10-08","epss":0.06946,"percentile":0.93954}],"risk":3.473,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35561"},"relatedVulnerabilities":[{"id":"CVE-2021-35561","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35561","date":"2026-10-08","epss":0.06946,"percentile":0.93954}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35561","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Utility). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"100fe9e3e8e98cf6","cpes":["cpe:2.3:a:libonig4:libonig4:6.7.0-1:*:*:*:*:*:*:*"],"name":"libonig4","purl":"pkg:deb/ubuntu/libonig4@6.7.0-1?arch=amd64&distro=ubuntu-18.04&upstream=libonig","type":"deb","version":"6.7.0-1","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libonig4/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libonig4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libonig4:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libonig4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libonig"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19204","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libonig","version":"6.7.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19204","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-19204","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19204","date":"2026-10-08","epss":0.06889,"percentile":0.93909}],"risk":3.4445000000000006,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19204"},"relatedVulnerabilities":[{"id":"CVE-2019-19204","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-19204","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19204","date":"2026-10-08","epss":0.06889,"percentile":0.93909}],"urls":["https://github.com/ManhNDd/CVE-2019-19204","https://github.com/kkos/oniguruma/issues/162","https://github.com/kkos/oniguruma/releases/tag/v6.9.4_rc2","https://github.com/tarantula-team/CVE-2019-19204","https://lists.debian.org/debian-lts-announce/2019/12/msg00002.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NO267PLHGYZSWX3XTRPKYBKD4J3YOU5V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3MBNW6Z4DOXSCNWGBLQ7OA3OGUJ44WL/","https://usn.ubuntu.com/4460-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19204","description":"An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read."}]},{"artifact":{"id":"91ad4ea54a8353ff","cpes":["cpe:2.3:a:perl-base:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.26.1-6ubuntu0.3?arch=amd64&distro=ubuntu-18.04&upstream=perl","type":"deb","version":"5.26.1-6ubuntu0.3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.26.1-6ubuntu0.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-10543","versionConstraint":"< 5.26.1-6ubuntu0.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"perl","version":"5.26.1-6ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-10543","fix":{"state":"fixed","versions":["5.26.1-6ubuntu0.5"],"available":[{"date":"2020-10-26","kind":"advisory","version":"5.26.1-6ubuntu0.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-10543","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10543","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10543","date":"2026-10-08","epss":0.11334,"percentile":0.95884}],"risk":3.4002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-10543"},"relatedVulnerabilities":[{"id":"CVE-2020-10543","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10543","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10543","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10543","date":"2026-10-08","epss":0.11334,"percentile":0.95884}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html","https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod","https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3","https://github.com/perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03ed","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/","https://security.gentoo.org/glsa/202006-03","https://security.netapp.com/advisory/ntap-20200611-0001/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10543","description":"Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35586","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35586","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35586","date":"2026-10-08","epss":0.0679,"percentile":0.93832}],"risk":3.395,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35586"},"relatedVulnerabilities":[{"id":"CVE-2021-35586","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35586","date":"2026-10-08","epss":0.0679,"percentile":0.93832}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35586","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.80"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q3mw-pvr8-9ggc","versionConstraint":">=9.0.0-M1,<9.0.80 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q3mw-pvr8-9ggc","fix":{"state":"fixed","versions":["9.0.80"],"available":[{"date":"2023-09-29","kind":"first-observed","version":"9.0.80"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-41080","cwe":"CWE-601","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2023-41080","date":"2026-10-08","epss":0.06047,"percentile":0.93187}],"risk":3.3560849999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-41080","https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f","https://github.com/apache/tomcat/commit/4998ad745b67edeadefe541c94ed029b53933d3b","https://github.com/apache/tomcat/commit/77c0ce2d169efa248b64b992e547aad549ec906b","https://github.com/apache/tomcat/commit/bb4624a9f3e69d495182ebfa68d7983076407a27","https://github.com/apache/tomcat/commit/e3703c9abb8fe0d5602f6ba8a8f11d4b6940815a","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522","https://security.netapp.com/advisory/ntap-20230921-0006"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q3mw-pvr8-9ggc","description":"Apache Tomcat Open Redirect vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2023-41080","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-41080","cwe":"CWE-601","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2023-41080","date":"2026-10-08","epss":0.06047,"percentile":0.93187}],"urls":["https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://security.netapp.com/advisory/ntap-20230921-0006/","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-41080","description":"URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.\nOlder, EOL versions may also be affected.\n\n\nThe vulnerability is limited to the ROOT (default) web application."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35578","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35578","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35578","date":"2026-10-08","epss":0.06679,"percentile":0.93732}],"risk":3.3395,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35578"},"relatedVulnerabilities":[{"id":"CVE-2021-35578","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35578","date":"2026-10-08","epss":0.06679,"percentile":0.93732}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35578","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8w26-6f25-cm9x","versionConstraint":">=2.0.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8w26-6f25-cm9x","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36185","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36185","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"risk":3.3048599999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36185","https://github.com/FasterXML/jackson-databind/issues/2998","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/567194c53ae91f0a14dc27239afb739b1c10448a"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8w26-6f25-cm9x","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36185","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36185","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36185","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2998","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36185","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r695-7vr9-jgc2","versionConstraint":">=2.0.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r695-7vr9-jgc2","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36187","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36187","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"risk":3.3048599999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36187","https://github.com/FasterXML/jackson-databind/issues/2997","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r695-7vr9-jgc2","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36187","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36187","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36187","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2997","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36187","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v585-23hc-c647","versionConstraint":">=2.0.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-v585-23hc-c647","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-11-30","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36186","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36186","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"risk":3.3048599999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36186","https://github.com/FasterXML/jackson-databind/issues/2997","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v585-23hc-c647","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36186","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36186","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36186","date":"2026-10-08","epss":0.04237,"percentile":0.9077}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2997","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36186","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource."}]},{"artifact":{"id":"3445236446ec4939","cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"krb5-locales","purl":"pkg:deb/ubuntu/krb5-locales@1.16-2ubuntu0.1?arch=all&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 1.16-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["1.16-2ubuntu0.3"],"available":[{"date":"2023-01-25","kind":"advisory","version":"1.16-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"c67e239bf70af34c","cpes":["cpe:2.3:a:libasn1-8-heimdal:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8-heimdal:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8_heimdal:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8_heimdal:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libasn1-8-heimdal","purl":"pkg:deb/ubuntu/libasn1-8-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libasn1-8-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libasn1-8-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasn1-8-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libasn1-8-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"f3fc35a2cb3401bd","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/ubuntu/libgssapi-krb5-2@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 1.16-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["1.16-2ubuntu0.3"],"available":[{"date":"2023-01-25","kind":"advisory","version":"1.16-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"489fa43422e60874","cpes":["cpe:2.3:a:libgssapi3-heimdal:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3-heimdal:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3_heimdal:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3_heimdal:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libgssapi3-heimdal","purl":"pkg:deb/ubuntu/libgssapi3-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi3-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libgssapi3-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi3-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libgssapi3-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"8af38808136cd0ba","cpes":["cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4_heimdal:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4_heimdal:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libhcrypto4-heimdal","purl":"pkg:deb/ubuntu/libhcrypto4-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libhcrypto4-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libhcrypto4-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhcrypto4-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libhcrypto4-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"4fe49c3e8d200f83","cpes":["cpe:2.3:a:libheimbase1-heimdal:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1-heimdal:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1_heimdal:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1_heimdal:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libheimbase1-heimdal","purl":"pkg:deb/ubuntu/libheimbase1-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheimbase1-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libheimbase1-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheimbase1-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libheimbase1-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"5ac1d9d8c3d94a69","cpes":["cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0_heimdal:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0_heimdal:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libheimntlm0-heimdal","purl":"pkg:deb/ubuntu/libheimntlm0-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheimntlm0-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libheimntlm0-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheimntlm0-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libheimntlm0-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"5aedfa9521e17f6a","cpes":["cpe:2.3:a:libhx509-5-heimdal:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5-heimdal:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5_heimdal:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5_heimdal:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libhx509-5-heimdal","purl":"pkg:deb/ubuntu/libhx509-5-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libhx509-5-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libhx509-5-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhx509-5-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libhx509-5-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"ce64c2275844a0e2","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/ubuntu/libk5crypto3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 1.16-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["1.16-2ubuntu0.3"],"available":[{"date":"2023-01-25","kind":"advisory","version":"1.16-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"ec3f5f14c892446a","cpes":["cpe:2.3:a:libkrb5-26-heimdal:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26-heimdal:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26_heimdal:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26_heimdal:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libkrb5-26-heimdal","purl":"pkg:deb/ubuntu/libkrb5-26-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-26-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5-26-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-26-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5-26-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"a0e77fe46f00e692","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/ubuntu/libkrb5-3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 1.16-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["1.16-2ubuntu0.3"],"available":[{"date":"2023-01-25","kind":"advisory","version":"1.16-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"402827dd4cb6593f","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/ubuntu/libkrb5support0@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 1.16-2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["1.16-2ubuntu0.3"],"available":[{"date":"2023-01-25","kind":"advisory","version":"1.16-2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"d29c0be392861a2d","cpes":["cpe:2.3:a:libroken18-heimdal:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18-heimdal:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18_heimdal:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18_heimdal:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libroken18-heimdal","purl":"pkg:deb/ubuntu/libroken18-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libroken18-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libroken18-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libroken18-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libroken18-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"4c95d1ed3ad0ede5","cpes":["cpe:2.3:a:libwind0-heimdal:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0-heimdal:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0_heimdal:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0_heimdal:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libwind0-heimdal","purl":"pkg:deb/ubuntu/libwind0-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwind0-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libwind0-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwind0-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libwind0-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-42898","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-42898","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"risk":3.2365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-42898"},"relatedVulnerabilities":[{"id":"CVE-2022-42898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42898","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42898","date":"2026-10-08","epss":0.06473,"percentile":0.93575}],"urls":["https://bugzilla.samba.org/show_bug.cgi?id=15203","https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3c","https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://security.netapp.com/advisory/ntap-20230223-0001/","https://web.mit.edu/kerberos/advisories/","https://web.mit.edu/kerberos/krb5-1.19/","https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txt","https://www.samba.org/samba/security/CVE-2022-42898.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42898","description":"PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \"a similar bug.\""}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cvm9-fjm9-3572","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cvm9-fjm9-3572","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36181","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36181","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36181","date":"2026-10-08","epss":0.04092,"percentile":0.90468}],"risk":3.19176,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36181","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cvm9-fjm9-3572","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36181","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36181","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36181","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36181","date":"2026-10-08","epss":0.04092,"percentile":0.90468}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/3004","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36181","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-89qr-369f-5m5x","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-89qr-369f-5m5x","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36182","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36182","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36182","date":"2026-10-08","epss":0.04092,"percentile":0.90467}],"risk":3.19176,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36182","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-89qr-369f-5m5x","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36182","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36182","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36182","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36182","date":"2026-10-08","epss":0.04092,"percentile":0.90467}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/3004","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36182","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8c4j-34r4-xr8g","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8c4j-34r4-xr8g","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36180","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36180","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36180","date":"2026-10-08","epss":0.04092,"percentile":0.90467}],"risk":3.19176,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36180","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8c4j-34r4-xr8g","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36180","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36180","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36180","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-36180","date":"2026-10-08","epss":0.04092,"percentile":0.90467}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/3004","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36180","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-26116","versionConstraint":"< 3.6.9-1~18.04ubuntu1.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-26116","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.3"],"available":[{"date":"2020-10-14","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-26116","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-26116","date":"2026-10-08","epss":0.06358,"percentile":0.93473}],"risk":3.179,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-26116"},"relatedVulnerabilities":[{"id":"CVE-2020-26116","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-26116","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-26116","date":"2026-10-08","epss":0.06358,"percentile":0.93473}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html","https://bugs.python.org/issue39603","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/","https://python-security.readthedocs.io/vuln/http-header-injection-method.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20201023-0001/","https://usn.ubuntu.com/4581-1/","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-26116","description":"http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-26116","versionConstraint":"< 3.6.9-1~18.04ubuntu1.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-26116","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.3"],"available":[{"date":"2020-10-14","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-26116","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-26116","date":"2026-10-08","epss":0.06358,"percentile":0.93473}],"risk":3.179,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-26116"},"relatedVulnerabilities":[{"id":"CVE-2020-26116","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-26116","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-26116","date":"2026-10-08","epss":0.06358,"percentile":0.93473}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html","https://bugs.python.org/issue39603","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/","https://python-security.readthedocs.io/vuln/http-header-injection-method.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20201023-0001/","https://usn.ubuntu.com/4581-1/","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-26116","description":"http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-26116","versionConstraint":"< 3.6.9-1~18.04ubuntu1.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-26116","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.3"],"available":[{"date":"2020-10-14","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-26116","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-26116","date":"2026-10-08","epss":0.06358,"percentile":0.93473}],"risk":3.179,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-26116"},"relatedVulnerabilities":[{"id":"CVE-2020-26116","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-26116","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-26116","date":"2026-10-08","epss":0.06358,"percentile":0.93473}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html","https://bugs.python.org/issue39603","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/","https://python-security.readthedocs.io/vuln/http-header-injection-method.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20201023-0001/","https://usn.ubuntu.com/4581-1/","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-26116","description":"http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-26116","versionConstraint":"< 3.6.9-1~18.04ubuntu1.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-26116","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.3"],"available":[{"date":"2020-10-14","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-26116","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-26116","date":"2026-10-08","epss":0.06358,"percentile":0.93473}],"risk":3.179,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-26116"},"relatedVulnerabilities":[{"id":"CVE-2020-26116","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-26116","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-26116","date":"2026-10-08","epss":0.06358,"percentile":0.93473}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html","https://bugs.python.org/issue39603","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/","https://python-security.readthedocs.io/vuln/http-header-injection-method.html","https://security.gentoo.org/glsa/202101-18","https://security.netapp.com/advisory/ntap-20201023-0001/","https://usn.ubuntu.com/4581-1/","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-26116","description":"http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.14"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-22924","versionConstraint":"< 7.58.0-2ubuntu3.14 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22924","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.14"],"available":[{"date":"2021-07-22","kind":"advisory","version":"7.58.0-2ubuntu3.14"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22924","cwe":"CWE-20","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22924","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22924","date":"2026-10-08","epss":0.0627,"percentile":0.93399}],"risk":3.1350000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22924"},"relatedVulnerabilities":[{"id":"CVE-2021-22924","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22924","cwe":"CWE-20","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22924","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22924","date":"2026-10-08","epss":0.0627,"percentile":0.93399}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-732250.pdf","https://hackerone.com/reports/1223565","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/","https://security.netapp.com/advisory/ntap-20210902-0003/","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22924","description":"libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.14"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-22924","versionConstraint":"< 7.58.0-2ubuntu3.14 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22924","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.14"],"available":[{"date":"2021-07-22","kind":"advisory","version":"7.58.0-2ubuntu3.14"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22924","cwe":"CWE-20","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22924","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22924","date":"2026-10-08","epss":0.0627,"percentile":0.93399}],"risk":3.1350000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22924"},"relatedVulnerabilities":[{"id":"CVE-2021-22924","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22924","cwe":"CWE-20","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22924","cwe":"CWE-706","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22924","date":"2026-10-08","epss":0.0627,"percentile":0.93399}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-732250.pdf","https://hackerone.com/reports/1223565","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/","https://security.netapp.com/advisory/ntap-20210902-0003/","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22924","description":"libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vfqx-33qm-g869","versionConstraint":">=2.7.0,<2.9.10.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vfqx-33qm-g869","fix":{"state":"fixed","versions":["2.9.10.8"],"available":[{"date":"2021-12-10","kind":"first-observed","version":"2.9.10.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36189","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36189","date":"2026-10-08","epss":0.03987,"percentile":0.90242}],"risk":3.1098600000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36189","https://github.com/FasterXML/jackson-databind/issues/2996","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vfqx-33qm-g869","description":"Unsafe Deserialization in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2020-36189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36189","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36189","date":"2026-10-08","epss":0.03987,"percentile":0.90242}],"urls":["https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/FasterXML/jackson-databind/issues/2996","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36189","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource."}]},{"artifact":{"id":"d12e5c57a00d0dbc","cpes":["cpe:2.3:a:org.springframework:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-web","purl":"pkg:maven/org.springframework/spring-web@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-web-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-web","archiveDigests":[{"value":"d5b064196dc014519e751df549b4cc6a753fb191","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-web-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-ccgv-vj62-xf9h","versionConstraint":"<=5.2.25.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-web","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-ccgv-vj62-xf9h","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22243","cwe":"CWE-601","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22243","date":"2026-10-08","epss":0.03967,"percentile":0.9019}],"risk":3.09426,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-22243","https://spring.io/security/cve-2024-22243","https://github.com/spring-projects/spring-framework/blob/main/spring-web/src/main/java/org/springframework/web/util/UriComponentsBuilder.java","https://security.netapp.com/advisory/ntap-20240524-0001","http://seclists.org/fulldisclosure/2024/Sep/24"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-ccgv-vj62-xf9h","description":"Spring Web vulnerable to Open Redirect or Server Side Request Forgery"},"relatedVulnerabilities":[{"id":"CVE-2024-22243","cvss":[{"type":"Secondary","source":"security@vmware.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22243","cwe":"CWE-601","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22243","date":"2026-10-08","epss":0.03967,"percentile":0.9019}],"urls":["https://security.netapp.com/advisory/ntap-20240524-0001/","https://spring.io/security/cve-2024-22243","http://seclists.org/fulldisclosure/2024/Sep/24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-22243","description":"Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks."}]},{"artifact":{"id":"ec8633c8f20aaf73","cpes":["cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-2:libsasl2_2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2-2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2_2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_2:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*"],"name":"libsasl2-2","purl":"pkg:deb/ubuntu/libsasl2-2@2.1.27~101-g0780600%2Bdfsg-3ubuntu2.1?arch=amd64&distro=ubuntu-18.04&upstream=cyrus-sasl2","type":"deb","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.1","language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libsasl2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-24407","versionConstraint":"< 2.1.27~101-g0780600+dfsg-3ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cyrus-sasl2","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-24407","fix":{"state":"fixed","versions":["2.1.27~101-g0780600+dfsg-3ubuntu2.4"],"available":[{"date":"2022-02-22","kind":"advisory","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"risk":3.0922500000000004,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-24407"},"relatedVulnerabilities":[{"id":"CVE-2022-24407","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6.5,"impactScore":6.5,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/23/4","https://github.com/cyrusimap/cyrus-sasl/blob/fdcd13ceaef8de684dc69008011fa865c5b4a3ac/docsrc/sasl/release-notes/2.1/index.rst","https://lists.debian.org/debian-lts-announce/2022/03/msg00002.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4FIXU75Q6RBNK6UYM7MQ3TCFGXR7AX4U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H26R4SMGM3WHXX4XYNNJB4YGFIL5UNF4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZC6BMPI3V3MC2IGNLN377ETUWO7QBIH/","https://security.netapp.com/advisory/ntap-20221007-0003/","https://www.cyrusimap.org/sasl/sasl/release-notes/2.1/index.html#new-in-2-1-28","https://www.debian.org/security/2022/dsa-5087","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24407","description":"In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement."}]},{"artifact":{"id":"55d6825795ce6b15","cpes":["cpe:2.3:a:libsasl2-modules:libsasl2-modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2_modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2-modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2_modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_modules:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*"],"name":"libsasl2-modules","purl":"pkg:deb/ubuntu/libsasl2-modules@2.1.27~101-g0780600%2Bdfsg-3ubuntu2.1?arch=amd64&distro=ubuntu-18.04&upstream=cyrus-sasl2","type":"deb","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.1","language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-modules/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libsasl2-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules:amd64.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libsasl2-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libsasl2-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-24407","versionConstraint":"< 2.1.27~101-g0780600+dfsg-3ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cyrus-sasl2","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-24407","fix":{"state":"fixed","versions":["2.1.27~101-g0780600+dfsg-3ubuntu2.4"],"available":[{"date":"2022-02-22","kind":"advisory","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"risk":3.0922500000000004,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-24407"},"relatedVulnerabilities":[{"id":"CVE-2022-24407","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6.5,"impactScore":6.5,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/23/4","https://github.com/cyrusimap/cyrus-sasl/blob/fdcd13ceaef8de684dc69008011fa865c5b4a3ac/docsrc/sasl/release-notes/2.1/index.rst","https://lists.debian.org/debian-lts-announce/2022/03/msg00002.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4FIXU75Q6RBNK6UYM7MQ3TCFGXR7AX4U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H26R4SMGM3WHXX4XYNNJB4YGFIL5UNF4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZC6BMPI3V3MC2IGNLN377ETUWO7QBIH/","https://security.netapp.com/advisory/ntap-20221007-0003/","https://www.cyrusimap.org/sasl/sasl/release-notes/2.1/index.html#new-in-2-1-28","https://www.debian.org/security/2022/dsa-5087","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24407","description":"In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement."}]},{"artifact":{"id":"0f2b15d96ccd9059","cpes":["cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules-db:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-modules-db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_modules_db:2.1.27\\~101-g0780600\\+dfsg-3ubuntu2.1:*:*:*:*:*:*:*"],"name":"libsasl2-modules-db","purl":"pkg:deb/ubuntu/libsasl2-modules-db@2.1.27~101-g0780600%2Bdfsg-3ubuntu2.1?arch=amd64&distro=ubuntu-18.04&upstream=cyrus-sasl2","type":"deb","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.1","language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-modules-db/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libsasl2-modules-db/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-24407","versionConstraint":"< 2.1.27~101-g0780600+dfsg-3ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cyrus-sasl2","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-24407","fix":{"state":"fixed","versions":["2.1.27~101-g0780600+dfsg-3ubuntu2.4"],"available":[{"date":"2022-02-22","kind":"advisory","version":"2.1.27~101-g0780600+dfsg-3ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"risk":3.0922500000000004,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-24407"},"relatedVulnerabilities":[{"id":"CVE-2022-24407","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6.5,"impactScore":6.5,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24407","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24407","date":"2026-10-08","epss":0.04123,"percentile":0.90534}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/23/4","https://github.com/cyrusimap/cyrus-sasl/blob/fdcd13ceaef8de684dc69008011fa865c5b4a3ac/docsrc/sasl/release-notes/2.1/index.rst","https://lists.debian.org/debian-lts-announce/2022/03/msg00002.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4FIXU75Q6RBNK6UYM7MQ3TCFGXR7AX4U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H26R4SMGM3WHXX4XYNNJB4YGFIL5UNF4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZC6BMPI3V3MC2IGNLN377ETUWO7QBIH/","https://security.netapp.com/advisory/ntap-20221007-0003/","https://www.cyrusimap.org/sasl/sasl/release-notes/2.1/index.html#new-in-2-1-28","https://www.debian.org/security/2022/dsa-5087","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24407","description":"In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qmqc-x3r4-6v39","versionConstraint":">=2.9.0,<2.9.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qmqc-x3r4-6v39","fix":{"state":"fixed","versions":["2.9.10"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.9.10"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-14893","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14893","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14893","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14893","date":"2026-10-08","epss":0.04091,"percentile":0.90465}],"risk":3.06825,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-14893","https://github.com/FasterXML/jackson-databind/issues/2469","https://github.com/FasterXML/jackson-databind/commit/998efd708284778f29d83d7962a9bd935c228317","https://access.redhat.com/errata/RHSA-2020:0729","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14893","https://security.netapp.com/advisory/ntap-20200327-0006/","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qmqc-x3r4-6v39","description":"Polymorphic deserialization of malicious object in jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2019-14893","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14893","cwe":"CWE-200","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14893","cwe":"CWE-502","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-14893","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14893","date":"2026-10-08","epss":0.04091,"percentile":0.90465}],"urls":["https://access.redhat.com/errata/RHSA-2020:0729","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14893","https://github.com/FasterXML/jackson-databind/issues/2469","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://security.netapp.com/advisory/ntap-20200327-0006/","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14893","description":"A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code."}]},{"artifact":{"id":"de33a7c2f29642ef","cpes":["cpe:2.3:a:com.squareup.retrofit2:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:retrofit2:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:retrofit:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:squareup:retrofit:2.1.0:*:*:*:*:*:*:*"],"name":"retrofit","purl":"pkg:maven/com.squareup.retrofit2/retrofit@2.1.0","type":"java-archive","version":"2.1.0","language":"java","licenses":[],"metadata":{"pomGroupID":"com.squareup.retrofit2","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/retrofit-2.1.0.jar","manifestName":"","pomArtifactID":"retrofit","archiveDigests":[{"value":"2de7cd8b95b7021b1d597f049bcb422055119f2c","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/retrofit-2.1.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8p8g-f9vg-r7xr","versionConstraint":">=2.0.0,<2.5.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.squareup.retrofit2:retrofit","version":"2.1.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8p8g-f9vg-r7xr","fix":{"state":"fixed","versions":["2.5.0"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.5.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000850","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000850","date":"2026-10-08","epss":0.04033,"percentile":0.90341}],"risk":3.0247499999999996,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-1000850","https://github.com/square/retrofit/commit/b9a7f6ad72073ddd40254c0058710e87a073047d#diff-943ec7ed35e68201824904d1dc0ec982","https://access.redhat.com/errata/RHSA-2019:3892","https://github.com/square/retrofit/blob/master/CHANGELOG.md","https://ihacktoprotect.com/post/retrofit-path-traversal/","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8p8g-f9vg-r7xr","description":"Directory Traversal vulnerability in Square Retrofit"},"relatedVulnerabilities":[{"id":"CVE-2018-1000850","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000850","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000850","date":"2026-10-08","epss":0.04033,"percentile":0.90341}],"urls":["https://access.redhat.com/errata/RHSA-2019:3892","https://github.com/square/retrofit/blob/master/CHANGELOG.md","https://github.com/square/retrofit/commit/b9a7f6ad72073ddd40254c0058710e87a073047d#diff-943ec7ed35e68201824904d1dc0ec982","https://ihacktoprotect.com/post/retrofit-path-traversal/","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000850","description":"Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.81"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r6j3-px5g-cq3x","versionConstraint":">=9.0.0-M1,<9.0.81 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r6j3-px5g-cq3x","fix":{"state":"fixed","versions":["9.0.81"],"available":[{"date":"2023-12-22","kind":"first-observed","version":"9.0.81"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45648","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2023-45648","cwe":"NVD-CWE-Other","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45648","date":"2026-10-08","epss":0.05848,"percentile":0.92995}],"risk":3.01172,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-45648","https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdp","http://www.openwall.com/lists/oss-security/2023/10/10/10","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522","https://github.com/apache/tomcat/commit/59583245639d8c42ae0009f4a4a70464d3ea70a0","https://github.com/apache/tomcat/commit/8ecff306507be8e4fd3adee1ae5de1ea6661a8f4","https://github.com/apache/tomcat/commit/eb5c094e5560764cda436362254997511a3ca1f6","https://github.com/apache/tomcat/commit/c83fe47725f7ae9ae213568d9039171124fb7ec6","https://security.netapp.com/advisory/ntap-20231103-0007"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r6j3-px5g-cq3x","description":"Apache Tomcat Improper Input Validation vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2023-45648","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45648","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2023-45648","cwe":"NVD-CWE-Other","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45648","date":"2026-10-08","epss":0.05848,"percentile":0.92995}],"urls":["https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdp","http://www.openwall.com/lists/oss-security/2023/10/10/10","https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","https://security.netapp.com/advisory/ntap-20231103-0007/","https://www.debian.org/security/2023/dsa-5521","https://www.debian.org/security/2023/dsa-5522"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45648","description":"Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially \ncrafted, invalid trailer header could cause Tomcat to treat a single \nrequest as multiple requests leading to the possibility of request \nsmuggling when behind a reverse proxy.\n\nOlder, EOL versions may also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45447","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2026-45447","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"risk":3.0015,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45447"},"relatedVulnerabilities":[{"id":"CVE-2026-45447","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"urls":["https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","https://openssl-library.org/news/secadv/20260609.txt","https://access.redhat.com/errata/RHSA-2026:25237","https://access.redhat.com/errata/RHSA-2026:25239","https://access.redhat.com/errata/RHSA-2026:26275","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:35869","https://access.redhat.com/errata/RHSA-2026:36215","https://access.redhat.com/errata/RHSA-2026:36217","https://access.redhat.com/errata/RHSA-2026:39009","https://access.redhat.com/errata/RHSA-2026:39012","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44438","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:58563","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:66524","https://access.redhat.com/security/cve/CVE-2026-45447","https://bugzilla.redhat.com/show_bug.cgi?id=2481898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-45447","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2026-45447","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"risk":3.0015,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45447"},"relatedVulnerabilities":[{"id":"CVE-2026-45447","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"urls":["https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","https://openssl-library.org/news/secadv/20260609.txt","https://access.redhat.com/errata/RHSA-2026:25237","https://access.redhat.com/errata/RHSA-2026:25239","https://access.redhat.com/errata/RHSA-2026:26275","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:35869","https://access.redhat.com/errata/RHSA-2026:36215","https://access.redhat.com/errata/RHSA-2026:36217","https://access.redhat.com/errata/RHSA-2026:39009","https://access.redhat.com/errata/RHSA-2026:39012","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44438","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:58563","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:66524","https://access.redhat.com/security/cve/CVE-2026-45447","https://bugzilla.redhat.com/show_bug.cgi?id=2481898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-58pp-9c76-5625","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-58pp-9c76-5625","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11112","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11112","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11112","date":"2026-10-08","epss":0.03643,"percentile":0.89274}],"risk":2.969045,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11112","https://github.com/FasterXML/jackson-databind/issues/2666","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-58pp-9c76-5625","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-11112","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11112","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11112","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11112","date":"2026-10-08","epss":0.03643,"percentile":0.89274}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2666","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11112","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rf6r-2c4q-2vwg","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rf6r-2c4q-2vwg","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10968","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10968","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10968","date":"2026-10-08","epss":0.03626,"percentile":0.89225}],"risk":2.9551900000000004,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10968","https://github.com/FasterXML/jackson-databind/issues/2662","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/05d7e0e13f43e12db6a51726df12c8b4d8040676","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://security.netapp.com/advisory/ntap-20200403-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rf6r-2c4q-2vwg","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-10968","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10968","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10968","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10968","date":"2026-10-08","epss":0.03626,"percentile":0.89225}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2662","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10968","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v3xw-c963-f5hc","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-v3xw-c963-f5hc","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11111","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11111","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11111","date":"2026-10-08","epss":0.03576,"percentile":0.89083}],"risk":2.91444,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11111","https://github.com/FasterXML/jackson-databind/issues/2664","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v3xw-c963-f5hc","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-11111","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11111","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-11111","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-11111","date":"2026-10-08","epss":0.03576,"percentile":0.89083}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2664","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11111","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms)."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-758m-v56v-grj4","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-758m-v56v-grj4","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10969","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10969","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10969","date":"2026-10-08","epss":0.0356,"percentile":0.89017}],"risk":2.9014,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10969","https://github.com/FasterXML/jackson-databind/issues/2642","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/6ba48457984943df0de92c54144f7dcae01b1221","https://security.netapp.com/advisory/ntap-20200403-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-758m-v56v-grj4","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-10969","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10969","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10969","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10969","date":"2026-10-08","epss":0.0356,"percentile":0.89017}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2642","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10969","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-27xj-rqx5-2255","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-27xj-rqx5-2255","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11619","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11619","date":"2026-10-08","epss":0.03714,"percentile":0.89476}],"risk":2.89692,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-11619","https://github.com/FasterXML/jackson-databind/issues/2680","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200511-0004"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-27xj-rqx5-2255","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-11619","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11619","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11619","date":"2026-10-08","epss":0.03714,"percentile":0.89476}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2680","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200511-0004/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11619","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop)."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-37454","versionConstraint":"< 3.6.9-1~18.04ubuntu1.10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-37454","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.10"],"available":[{"date":"2023-03-06","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.10"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37454","date":"2026-10-08","epss":0.05765,"percentile":0.92888}],"risk":2.8825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-37454"},"relatedVulnerabilities":[{"id":"CVE-2022-37454","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37454","date":"2026-10-08","epss":0.05765,"percentile":0.92888}],"urls":["https://csrc.nist.gov/projects/hash-functions/sha-3-project","https://eprint.iacr.org/2023/331","https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658","https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html","https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/","https://mouha.be/sha-3-buffer-overflow/","https://news.ycombinator.com/item?id=33281106","https://news.ycombinator.com/item?id=35050307","https://security.gentoo.org/glsa/202305-02","https://www.debian.org/security/2022/dsa-5267","https://www.debian.org/security/2022/dsa-5269","https://security.netapp.com/advisory/ntap-20230203-0001/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-37454","description":"The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-37454","versionConstraint":"< 3.6.9-1~18.04ubuntu1.10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-37454","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.10"],"available":[{"date":"2023-03-06","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.10"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37454","date":"2026-10-08","epss":0.05765,"percentile":0.92888}],"risk":2.8825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-37454"},"relatedVulnerabilities":[{"id":"CVE-2022-37454","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37454","date":"2026-10-08","epss":0.05765,"percentile":0.92888}],"urls":["https://csrc.nist.gov/projects/hash-functions/sha-3-project","https://eprint.iacr.org/2023/331","https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658","https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html","https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/","https://mouha.be/sha-3-buffer-overflow/","https://news.ycombinator.com/item?id=33281106","https://news.ycombinator.com/item?id=35050307","https://security.gentoo.org/glsa/202305-02","https://www.debian.org/security/2022/dsa-5267","https://www.debian.org/security/2022/dsa-5269","https://security.netapp.com/advisory/ntap-20230203-0001/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-37454","description":"The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-37454","versionConstraint":"< 3.6.9-1~18.04ubuntu1.10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-37454","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.10"],"available":[{"date":"2023-03-06","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.10"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37454","date":"2026-10-08","epss":0.05765,"percentile":0.92888}],"risk":2.8825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-37454"},"relatedVulnerabilities":[{"id":"CVE-2022-37454","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37454","date":"2026-10-08","epss":0.05765,"percentile":0.92888}],"urls":["https://csrc.nist.gov/projects/hash-functions/sha-3-project","https://eprint.iacr.org/2023/331","https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658","https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html","https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/","https://mouha.be/sha-3-buffer-overflow/","https://news.ycombinator.com/item?id=33281106","https://news.ycombinator.com/item?id=35050307","https://security.gentoo.org/glsa/202305-02","https://www.debian.org/security/2022/dsa-5267","https://www.debian.org/security/2022/dsa-5269","https://security.netapp.com/advisory/ntap-20230203-0001/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-37454","description":"The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-37454","versionConstraint":"< 3.6.9-1~18.04ubuntu1.10 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-37454","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.10"],"available":[{"date":"2023-03-06","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.10"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37454","date":"2026-10-08","epss":0.05765,"percentile":0.92888}],"risk":2.8825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-37454"},"relatedVulnerabilities":[{"id":"CVE-2022-37454","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-37454","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-37454","date":"2026-10-08","epss":0.05765,"percentile":0.92888}],"urls":["https://csrc.nist.gov/projects/hash-functions/sha-3-project","https://eprint.iacr.org/2023/331","https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658","https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html","https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/","https://mouha.be/sha-3-buffer-overflow/","https://news.ycombinator.com/item?id=33281106","https://news.ycombinator.com/item?id=35050307","https://security.gentoo.org/glsa/202305-02","https://www.debian.org/security/2022/dsa-5267","https://www.debian.org/security/2022/dsa-5269","https://security.netapp.com/advisory/ntap-20230203-0001/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-37454","description":"The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35564","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35564","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35564","date":"2026-10-08","epss":0.0563,"percentile":0.92749}],"risk":2.815,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35564"},"relatedVulnerabilities":[{"id":"CVE-2021-35564","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35564","date":"2026-10-08","epss":0.0563,"percentile":0.92749}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WTVCIVHTX3XONYOEGUMLKCM4QEC6INT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJILEHYV2U37HKMGFEQ7CAVOV4DUWW2O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V362B2BWTH5IJDL45QPQGMBKIQOG7JX5/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35564","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Keytool). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"f25fc1bd06b6f8af","cpes":["cpe:2.3:a:com.google.guava:guava:20.0:*:*:*:*:*:*:*","cpe:2.3:a:google:guava:20.0:*:*:*:*:*:*:*","cpe:2.3:a:guava:guava:20.0:*:*:*:*:*:*:*"],"name":"guava","purl":"pkg:maven/com.google.guava/guava@20.0","type":"java-archive","version":"20.0","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.google.guava","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/guava-20.0.jar","manifestName":"","pomArtifactID":"guava","archiveDigests":[{"value":"89507701249388e1ed5ddcf8c41f4ce1be7831ef","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/guava-20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"24.1.1-android"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mvr2-9pj6-7w5j","versionConstraint":">=11.0,<24.1.1-android (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.google.guava:guava","version":"20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mvr2-9pj6-7w5j","fix":{"state":"fixed","versions":["24.1.1-android"],"available":[{"date":"2023-11-10","kind":"first-observed","version":"24.1.1-android"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-10237","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10237","date":"2026-10-08","epss":0.05086,"percentile":0.92131}],"risk":2.7718700000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-10237","https://github.com/google/guava/wiki/CVE-2018-10237","https://groups.google.com/d/topic/guava-announce/xqWALw4W1vs/discussion","http://www.securitytracker.com/id/1041707","https://access.redhat.com/errata/RHSA-2018:2423","https://access.redhat.com/errata/RHSA-2018:2424","https://access.redhat.com/errata/RHSA-2018:2425","https://access.redhat.com/errata/RHSA-2018:2428","https://access.redhat.com/errata/RHSA-2018:2598","https://access.redhat.com/errata/RHSA-2018:2643","https://access.redhat.com/errata/RHSA-2018:2740","https://access.redhat.com/errata/RHSA-2018:2741","https://access.redhat.com/errata/RHSA-2018:2742","https://access.redhat.com/errata/RHSA-2018:2743","https://access.redhat.com/errata/RHSA-2018:2927","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/19fa48533bc7ea1accf6b12746a74ed888ae6e49a5cf81ae4f807495@%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/33c6bccfeb7adf644d4d79894ca8f09370be6ed4b20632c2e228d085@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/3d5dbdd92ac9ceaef90e40f78599f9109f2f345252e0ac9d98e7e084@%3Cgitbox.activemq.apache.org%3E","https://lists.apache.org/thread.html/3ddd79c801edd99c0978e83dbe2168ebd36fd42acfa5dac38fb03dd6@%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/cc48fe770c45a74dc3b37ed0817393e0c96701fc49bc431ed922f3cc@%3Chdfs-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r27eb79a87a760335226dbfa6a7b7bffea539a535f8e80c41e482106d@%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r2ea4e5e5aa8ad73b001a466c582899620961f47d77a40af712c1fdf9@%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r38e2ab87528d3c904e7fac496e8fd766b9277656ff95b97d6b6b6dcd@%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r43491b25b2e5c368c34b106a82eff910a5cea3e90de82ad75cc16540@%3Cdev.syncope.apache.org%3E","https://lists.apache.org/thread.html/r95799427b335807a4c54776908125c3e66597b65845ae50096d9278a@%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/ra0adb9653c7de9539b93cc8434143b655f753b9f60580ff260becb2b@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/rc78f6e84f82cc662860e96526d8ab969f34dbe12dc560e22d9d147a3@%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/rc8467f357b943ceaa86f289f8bc1a5d1c7955b75d3bac1426f2d4ac1@%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rd0c8ec6e044aa2958dd0549ebf8ecead7f5968c9474ba73a504161b2@%3Cdev.cxf.apache.org%3E","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r02e39d7beb32eebcdbb4b516e95f67d71c90d5d462b26f4078d21eeb@%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/r02e39d7beb32eebcdbb4b516e95f67d71c90d5d462b26f4078d21eeb@%3Cuser.flink.apache.org%3E","https://lists.apache.org/thread.html/r223bc776a077d0795786c38cbc6e7dd808fce1a9161b00ba9c0a5d55@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/r50fc0bcc734dd82e691d36d209258683141bfc0083739a77e56ad92d@%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/ra4f44016926dcb034b3b230280a18102062f94ae55b8a31bb92fed84@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/ra8906723927aef2a599398c238eacfc845b74d812e0093ec2fc70a7d@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/rb3da574c34bc6bd37972d2266af3093b90d7e437460423c24f477919@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/rdc56c15693c236e31e1e95f847b8e5e74fc0a05741d47488e7fc8c45@%3Cissues.flink.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r22c8173b804cd4a420c43064ba4e363d0022aa421008b1989f7354d4@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r30e7d7b6bfa630dacc41649a0e96dad75165d50474c1241068aa0f94@%3Cissues.storm.apache.org%3E","https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21@%3Ccommits.samza.apache.org%3E","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95@%3Cgithub.arrow.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2021.html","https://security.netapp.com/advisory/ntap-20220629-0008/"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mvr2-9pj6-7w5j","description":"Denial of Service in Google Guava"},"relatedVulnerabilities":[{"id":"CVE-2018-10237","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-10237","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10237","date":"2026-10-08","epss":0.05086,"percentile":0.92131}],"urls":["http://www.securitytracker.com/id/1041707","https://access.redhat.com/errata/RHSA-2018:2423","https://access.redhat.com/errata/RHSA-2018:2424","https://access.redhat.com/errata/RHSA-2018:2425","https://access.redhat.com/errata/RHSA-2018:2428","https://access.redhat.com/errata/RHSA-2018:2598","https://access.redhat.com/errata/RHSA-2018:2643","https://access.redhat.com/errata/RHSA-2018:2740","https://access.redhat.com/errata/RHSA-2018:2741","https://access.redhat.com/errata/RHSA-2018:2742","https://access.redhat.com/errata/RHSA-2018:2743","https://access.redhat.com/errata/RHSA-2018:2927","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://groups.google.com/d/topic/guava-announce/xqWALw4W1vs/discussion","https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/19fa48533bc7ea1accf6b12746a74ed888ae6e49a5cf81ae4f807495%40%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/33c6bccfeb7adf644d4d79894ca8f09370be6ed4b20632c2e228d085%40%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/3d5dbdd92ac9ceaef90e40f78599f9109f2f345252e0ac9d98e7e084%40%3Cgitbox.activemq.apache.org%3E","https://lists.apache.org/thread.html/3ddd79c801edd99c0978e83dbe2168ebd36fd42acfa5dac38fb03dd6%40%3Cissues.activemq.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/cc48fe770c45a74dc3b37ed0817393e0c96701fc49bc431ed922f3cc%40%3Chdfs-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r02e39d7beb32eebcdbb4b516e95f67d71c90d5d462b26f4078d21eeb%40%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/r02e39d7beb32eebcdbb4b516e95f67d71c90d5d462b26f4078d21eeb%40%3Cuser.flink.apache.org%3E","https://lists.apache.org/thread.html/r223bc776a077d0795786c38cbc6e7dd808fce1a9161b00ba9c0a5d55%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/r22c8173b804cd4a420c43064ba4e363d0022aa421008b1989f7354d4%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r27eb79a87a760335226dbfa6a7b7bffea539a535f8e80c41e482106d%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r2ea4e5e5aa8ad73b001a466c582899620961f47d77a40af712c1fdf9%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r30e7d7b6bfa630dacc41649a0e96dad75165d50474c1241068aa0f94%40%3Cissues.storm.apache.org%3E","https://lists.apache.org/thread.html/r352e40ca9874d1beb4ad95403792adca7eb295e6bc3bd7b65fabcc21%40%3Ccommits.samza.apache.org%3E","https://lists.apache.org/thread.html/r38e2ab87528d3c904e7fac496e8fd766b9277656ff95b97d6b6b6dcd%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r43491b25b2e5c368c34b106a82eff910a5cea3e90de82ad75cc16540%40%3Cdev.syncope.apache.org%3E","https://lists.apache.org/thread.html/r50fc0bcc734dd82e691d36d209258683141bfc0083739a77e56ad92d%40%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r95799427b335807a4c54776908125c3e66597b65845ae50096d9278a%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/ra0adb9653c7de9539b93cc8434143b655f753b9f60580ff260becb2b%40%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/ra4f44016926dcb034b3b230280a18102062f94ae55b8a31bb92fed84%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/ra8906723927aef2a599398c238eacfc845b74d812e0093ec2fc70a7d%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/rb3da574c34bc6bd37972d2266af3093b90d7e437460423c24f477919%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/rc78f6e84f82cc662860e96526d8ab969f34dbe12dc560e22d9d147a3%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/rc8467f357b943ceaa86f289f8bc1a5d1c7955b75d3bac1426f2d4ac1%40%3Ccommon-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95%40%3Cgithub.arrow.apache.org%3E","https://lists.apache.org/thread.html/rd0c8ec6e044aa2958dd0549ebf8ecead7f5968c9474ba73a504161b2%40%3Cdev.cxf.apache.org%3E","https://lists.apache.org/thread.html/rdc56c15693c236e31e1e95f847b8e5e74fc0a05741d47488e7fc8c45%40%3Cissues.flink.apache.org%3E","https://security.netapp.com/advisory/ntap-20220629-0008/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10237","description":"Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable."}]},{"artifact":{"id":"685ff832fa5df143","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19591","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-19591","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"risk":2.766,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19591"},"relatedVulnerabilities":[{"id":"CVE-2018-19591","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"urls":["http://www.securityfocus.com/bid/106037","http://www.securitytracker.com/id/1042174","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO7WHN52GFMC5F2I2232GFIPSSXWFV7G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M52KE4YR3GNMHQUOS3DKAGZD5TQ5D5UH/","https://security.gentoo.org/glsa/201903-09","https://security.gentoo.org/glsa/201908-06","https://security.netapp.com/advisory/ntap-20190321-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=23927","https://sourceware.org/git/?p=glibc.git%3Ba=blob_plain%3Bf=NEWS%3Bhb=HEAD","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=d527c860f5a3f0ed687bd03f0cb464612dc23408","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19591","description":"In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function."}]},{"artifact":{"id":"71315b6fa75a7166","cpes":["cpe:2.3:a:libc6:libc6:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19591","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-19591","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"risk":2.766,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19591"},"relatedVulnerabilities":[{"id":"CVE-2018-19591","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"urls":["http://www.securityfocus.com/bid/106037","http://www.securitytracker.com/id/1042174","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO7WHN52GFMC5F2I2232GFIPSSXWFV7G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M52KE4YR3GNMHQUOS3DKAGZD5TQ5D5UH/","https://security.gentoo.org/glsa/201903-09","https://security.gentoo.org/glsa/201908-06","https://security.netapp.com/advisory/ntap-20190321-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=23927","https://sourceware.org/git/?p=glibc.git%3Ba=blob_plain%3Bf=NEWS%3Bhb=HEAD","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=d527c860f5a3f0ed687bd03f0cb464612dc23408","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19591","description":"In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function."}]},{"artifact":{"id":"62a0389fd254614a","cpes":["cpe:2.3:a:locales:locales:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.27-3ubuntu1?arch=all&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19591","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-19591","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"risk":2.766,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19591"},"relatedVulnerabilities":[{"id":"CVE-2018-19591","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"urls":["http://www.securityfocus.com/bid/106037","http://www.securitytracker.com/id/1042174","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO7WHN52GFMC5F2I2232GFIPSSXWFV7G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M52KE4YR3GNMHQUOS3DKAGZD5TQ5D5UH/","https://security.gentoo.org/glsa/201903-09","https://security.gentoo.org/glsa/201908-06","https://security.netapp.com/advisory/ntap-20190321-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=23927","https://sourceware.org/git/?p=glibc.git%3Ba=blob_plain%3Bf=NEWS%3Bhb=HEAD","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=d527c860f5a3f0ed687bd03f0cb464612dc23408","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19591","description":"In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function."}]},{"artifact":{"id":"6c475aa8af85f1cd","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19591","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-19591","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"risk":2.766,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-19591"},"relatedVulnerabilities":[{"id":"CVE-2018-19591","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19591","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-19591","cwe":"CWE-404","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-19591","date":"2026-10-08","epss":0.05532,"percentile":0.92616}],"urls":["http://www.securityfocus.com/bid/106037","http://www.securitytracker.com/id/1042174","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO7WHN52GFMC5F2I2232GFIPSSXWFV7G/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M52KE4YR3GNMHQUOS3DKAGZD5TQ5D5UH/","https://security.gentoo.org/glsa/201903-09","https://security.gentoo.org/glsa/201908-06","https://security.netapp.com/advisory/ntap-20190321-0003/","https://sourceware.org/bugzilla/show_bug.cgi?id=23927","https://sourceware.org/git/?p=glibc.git%3Ba=blob_plain%3Bf=NEWS%3Bhb=HEAD","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=d527c860f5a3f0ed687bd03f0cb464612dc23408","https://usn.ubuntu.com/4416-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19591","description":"In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.108"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gqp3-2cvr-x8m3","versionConstraint":">=9.0.0.M1,<9.0.108 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gqp3-2cvr-x8m3","fix":{"state":"fixed","versions":["9.0.108"],"available":[{"date":"2025-08-23","kind":"first-observed","version":"9.0.108"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48989","cwe":"CWE-404","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48989","date":"2026-10-08","epss":0.03686,"percentile":0.89395}],"risk":2.7644999999999995,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48989","https://lists.apache.org/thread/9ydfg0xr0tchmglcprhxgwhj0hfwxlyf","https://github.com/apache/tomcat/commit/73c04a10395774bda71a0b37802cf983662ce255","https://github.com/apache/tomcat/commit/f362c8eb3b8ec5b7f312f7f5610731c0fb299a06","https://github.com/apache/tomcat/commit/f36b8a4eea4ce8a0bc035079e1d259d29f5eb7bf","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-9.html","https://www.kb.cert.org/vuls/id/767506","http://www.openwall.com/lists/oss-security/2025/08/13/2","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gqp3-2cvr-x8m3","description":"Apache Tomcat Improper Resource Shutdown or Release vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2025-48989","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48989","cwe":"CWE-404","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48989","date":"2026-10-08","epss":0.03686,"percentile":0.89395}],"urls":["https://lists.apache.org/thread/9ydfg0xr0tchmglcprhxgwhj0hfwxlyf","http://www.openwall.com/lists/oss-security/2025/08/13/2","https://www.kb.cert.org/vuls/id/767506","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48989","description":"Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.\n\nUsers are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rpr3-cw39-3pxh","versionConstraint":"<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rpr3-cw39-3pxh","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2022-07-16","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10650","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10650","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10650","date":"2026-10-08","epss":0.03471,"percentile":0.88752}],"risk":2.7073799999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10650","https://github.com/FasterXML/jackson-databind/issues/2658","https://github.com/luisgarciacheckmarx/LGV_onefile/issues/19","https://github.com/FasterXML/jackson-databind/pull/2864","https://github.com/FasterXML/jackson-databind/commit/a424c038ba0c0d65e579e22001dec925902ac0ef","https://www.oracle.com/security-alerts/cpujan2021.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpuoct2022.html","https://lists.debian.org/debian-lts-announce/2023/04/msg00032.html","https://security.netapp.com/advisory/ntap-20230818-0007"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rpr3-cw39-3pxh","description":"jackson-databind vulnerable to unsafe deserialization"},"relatedVulnerabilities":[{"id":"CVE-2020-10650","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10650","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10650","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10650","date":"2026-10-08","epss":0.03471,"percentile":0.88752}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a424c038ba0c0d65e579e22001dec925902ac0ef","https://github.com/FasterXML/jackson-databind/issues/2658","https://github.com/advisories/GHSA-rpr3-cw39-3pxh","https://lists.debian.org/debian-lts-announce/2023/04/msg00032.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20230818-0007/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10650","description":"A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider."}]},{"artifact":{"id":"e268379bae5d9fad","cpes":["cpe:2.3:a:org.springframework.security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:security:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-security-web","purl":"pkg:maven/org.springframework.security/spring-security-web@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.security","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-web-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-security-web","archiveDigests":[{"value":"a9ff06ad3fd66cd08545e1a601c66d2256c86e0f","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-web-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gq28-h5vg-8prx","versionConstraint":"<5.2.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.security:spring-security-web","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gq28-h5vg-8prx","fix":{"state":"fixed","versions":["5.2.9"],"available":[{"date":"2021-05-11","kind":"first-observed","version":"5.2.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-22112","date":"2026-10-08","epss":0.03286,"percentile":0.88127}],"risk":2.6780900000000005,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-22112","https://github.com/spring-projects/spring-security/releases/tag/5.4.4","https://tanzu.vmware.com/security/cve-2021-22112","https://www.jenkins.io/security/advisory/2021-02-19/","http://www.openwall.com/lists/oss-security/2021/02/19/7","https://lists.apache.org/thread.html/redbd004a503b3520ae5746c2ab5e93fd7da807a8c128e60d2002cd9b@%3Cissues.nifi.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r2cb05e499807900ba23e539643eead9c5f0652fd271f223f89da1804@%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/r37423ec7eea340e92a409452c35b649dce02fdc467f0b3f52086c177@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/ra6389b1b82108a3b6bbcd22979f7665fd437c2a3408c9509a15a9ca1@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r163b3e4e39803882f5be05ee8606b2b9812920e196daa2a82997ce14@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r3868207b967f926819fe3aa8d33f1666429be589bb4a62104a49f4e3@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r390783b3b1c59b978131ac08390bf77fbb3863270cbde59d5b0f5fde@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r413e380088c427f56102968df89ef2f336473e1b56b7d4b3a571a378@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r89aa1b48a827f5641310305214547f1d6b2101971a49b624737c497f@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/ra53677224fe4f04c2599abc88032076faa18dc84b329cdeba85d4cfc@%3Cpluto-scm.portals.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gq28-h5vg-8prx","description":"Privilege escalation in spring security"},"relatedVulnerabilities":[{"id":"CVE-2021-22112","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-22112","date":"2026-10-08","epss":0.03286,"percentile":0.88127}],"urls":["http://www.openwall.com/lists/oss-security/2021/02/19/7","https://lists.apache.org/thread.html/r163b3e4e39803882f5be05ee8606b2b9812920e196daa2a82997ce14%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r2cb05e499807900ba23e539643eead9c5f0652fd271f223f89da1804%40%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/r37423ec7eea340e92a409452c35b649dce02fdc467f0b3f52086c177%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r3868207b967f926819fe3aa8d33f1666429be589bb4a62104a49f4e3%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r390783b3b1c59b978131ac08390bf77fbb3863270cbde59d5b0f5fde%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r413e380088c427f56102968df89ef2f336473e1b56b7d4b3a571a378%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/r89aa1b48a827f5641310305214547f1d6b2101971a49b624737c497f%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/ra53677224fe4f04c2599abc88032076faa18dc84b329cdeba85d4cfc%40%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/ra6389b1b82108a3b6bbcd22979f7665fd437c2a3408c9509a15a9ca1%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/redbd004a503b3520ae5746c2ab5e93fd7da807a8c128e60d2002cd9b%40%3Cissues.nifi.apache.org%3E","https://tanzu.vmware.com/security/cve-2021-22112","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22112","description":"Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application."}]},{"artifact":{"id":"839771142f972cee","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.30.0-1ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.30.0-1ubuntu1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/ubuntu/libnghttp2-14@1.30.0-1ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=nghttp2","type":"deb","version":"1.30.0-1ubuntu1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","SIL-OFL-1.1","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-11080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nghttp2","version":"1.30.0-1ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-11080","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-11080","cwe":"CWE-707","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2020-11080","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11080","date":"2026-10-08","epss":0.05316,"percentile":0.92393}],"risk":2.658,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-11080"},"relatedVulnerabilities":[{"id":"CVE-2020-11080","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-11080","cwe":"CWE-707","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2020-11080","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-11080","date":"2026-10-08","epss":0.05316,"percentile":0.92393}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html","https://github.com/nghttp2/nghttp2/commit/336a98feb0d56b9ac54e12736b18785c27f75090","https://github.com/nghttp2/nghttp2/commit/f8da73bd042f810f34d19f9eae02b46d870af394","https://github.com/nghttp2/nghttp2/security/advisories/GHSA-q5wr-xfw9-q7xr","https://lists.debian.org/debian-lts-announce/2021/10/msg00011.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AAC2AA36OTRHKSVM5OV7TTVB3CZIGEFL/","https://www.debian.org/security/2020/dsa-4696","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11080","description":"In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-22876","versionConstraint":"< 7.58.0-2ubuntu3.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22876","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.13"],"available":[{"date":"2021-03-31","kind":"advisory","version":"7.58.0-2ubuntu3.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22876","cwe":"CWE-359","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22876","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22876","date":"2026-10-08","epss":0.05301,"percentile":0.92378}],"risk":2.6505,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22876"},"relatedVulnerabilities":[{"id":"CVE-2021-22876","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22876","cwe":"CWE-359","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22876","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22876","date":"2026-10-08","epss":0.05301,"percentile":0.92378}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2021-22876.html","https://hackerone.com/reports/1101882","https://lists.debian.org/debian-lts-announce/2021/05/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZC5BMIOKLBQJSFCHEDN2G2C2SH274BP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITVWPVGLFISU5BJC2BXBRYSDXTXE2YGC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQUIOYX2KUU6FIUZVB5WWZ6JHSSYSQWJ/","https://security.gentoo.org/glsa/202105-36","https://security.netapp.com/advisory/ntap-20210521-0007/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22876","description":"curl 7.1.1 to and including 7.75.0 is vulnerable to an \"Exposure of Private Personal Information to an Unauthorized Actor\" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-22876","versionConstraint":"< 7.58.0-2ubuntu3.13 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22876","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.13"],"available":[{"date":"2021-03-31","kind":"advisory","version":"7.58.0-2ubuntu3.13"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22876","cwe":"CWE-359","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22876","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22876","date":"2026-10-08","epss":0.05301,"percentile":0.92378}],"risk":2.6505,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22876"},"relatedVulnerabilities":[{"id":"CVE-2021-22876","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22876","cwe":"CWE-359","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22876","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22876","date":"2026-10-08","epss":0.05301,"percentile":0.92378}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2021-22876.html","https://hackerone.com/reports/1101882","https://lists.debian.org/debian-lts-announce/2021/05/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZC5BMIOKLBQJSFCHEDN2G2C2SH274BP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITVWPVGLFISU5BJC2BXBRYSDXTXE2YGC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQUIOYX2KUU6FIUZVB5WWZ6JHSSYSQWJ/","https://security.gentoo.org/glsa/202105-36","https://security.netapp.com/advisory/ntap-20210521-0007/","https://www.oracle.com//security-alerts/cpujul2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22876","description":"curl 7.1.1 to and including 7.75.0 is vulnerable to an \"Exposure of Private Personal Information to an Unauthorized Actor\" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.12.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rgv9-q543-rqg4","versionConstraint":">=2.4.0-rc1,<2.12.7.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rgv9-q543-rqg4","fix":{"state":"fixed","versions":["2.12.7.1"],"available":[{"date":"2022-11-16","kind":"first-observed","version":"2.12.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42004","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42004","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42004","date":"2026-10-08","epss":0.03409,"percentile":0.88544}],"risk":2.6164075,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-42004","https://github.com/FasterXML/jackson-databind/issues/3582","https://github.com/FasterXML/jackson-databind/commit/063183589218fec19a9293ed2f17ec53ea80ba88","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50490","https://security.gentoo.org/glsa/202210-21","https://www.debian.org/security/2022/dsa-5283","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://github.com/FasterXML/jackson-databind/commit/35de19e7144c4df8ab178b800ba86e80c3d84252","https://github.com/FasterXML/jackson-databind/commit/cd090979b7ea78c75e4de8a4aed04f7e9fa8deea","https://security.netapp.com/advisory/ntap-20221118-0008","https://github.com/FasterXML/jackson-databind/commit/0e37a39502439ecbaa1a5b5188387c01bf7f7fa1"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rgv9-q543-rqg4","description":"Uncontrolled Resource Consumption in FasterXML jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2022-42004","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42004","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42004","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42004","date":"2026-10-08","epss":0.03409,"percentile":0.88544}],"urls":["https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50490","https://github.com/FasterXML/jackson-databind/commit/063183589218fec19a9293ed2f17ec53ea80ba88","https://github.com/FasterXML/jackson-databind/issues/3582","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://security.gentoo.org/glsa/202210-21","https://security.netapp.com/advisory/ntap-20221118-0008/","https://www.debian.org/security/2022/dsa-5283"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42004","description":"In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14562","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14562","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14562","date":"2026-10-08","epss":0.05166,"percentile":0.92227}],"risk":2.5829999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14562"},"relatedVulnerabilities":[{"id":"CVE-2020-14562","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14562","date":"2026-10-08","epss":0.05166,"percentile":0.92227}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14562","description":"Vulnerability in the Java SE product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"74ca91c067542bc8","cpes":["cpe:2.3:a:logback-core:logback-core:1.2.3:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.2.3:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.2.3:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.2.3:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.2.3:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.2.3:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.2.3","type":"java-archive","version":"1.2.3","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/logback-core-1.2.3.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"864344400c3d4d92dfeb0a305dc87d953677c03c","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/logback-core-1.2.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.2.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-668q-qrv7-99fm","versionConstraint":"<1.2.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.2.3"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-668q-qrv7-99fm","fix":{"state":"fixed","versions":["1.2.9"],"available":[{"date":"2022-03-29","kind":"first-observed","version":"1.2.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-42550","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"},{"cve":"CVE-2021-42550","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-42550","date":"2026-10-08","epss":0.04439,"percentile":0.91154}],"risk":2.5746199999999995,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-42550","https://github.com/cn-panda/logbackRceDemo","https://jira.qos.ch/browse/LOGBACK-1591","http://logback.qos.ch/news.html","https://github.com/qos-ch/logback/commit/87291079a1de9369ac67e20dc70a8fdc7cc4359c","https://github.com/qos-ch/logback/commit/ef4fc4186b74b45ce80d86833820106ff27edd42","https://github.com/qos-ch/logback/blob/1502cba4c1dfd135b2e715bc0cf80c0045d4d128/logback-site/src/site/pages/news.html","https://security.netapp.com/advisory/ntap-20211229-0001/","http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html","http://seclists.org/fulldisclosure/2022/Jul/11","https://cert-portal.siemens.com/productcert/pdf/ssa-371761.pdf"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-668q-qrv7-99fm","description":"Deserialization of Untrusted Data in logback"},"relatedVulnerabilities":[{"id":"CVE-2021-42550","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","metrics":{"baseScore":8.5,"impactScore":10.1,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-42550","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"},{"cve":"CVE-2021-42550","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-42550","date":"2026-10-08","epss":0.04439,"percentile":0.91154}],"urls":["http://logback.qos.ch/news.html","http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html","http://seclists.org/fulldisclosure/2022/Jul/11","https://cert-portal.siemens.com/productcert/pdf/ssa-371761.pdf","https://github.com/cn-panda/logbackRceDemo","https://jira.qos.ch/browse/LOGBACK-1591","https://security.netapp.com/advisory/ntap-20211229-0001/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-42550","description":"In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.12.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjjh-jjxp-wpff","versionConstraint":">=2.4.0-rc1,<2.12.7.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jjjh-jjxp-wpff","fix":{"state":"fixed","versions":["2.12.7.1"],"available":[{"date":"2022-11-16","kind":"first-observed","version":"2.12.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42003","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42003","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42003","date":"2026-10-08","epss":0.03409,"percentile":0.88545}],"risk":2.55675,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-42003","https://github.com/FasterXML/jackson-databind/issues/3590","https://github.com/FasterXML/jackson-databind/commit/d78d00ee7b5245b93103fef3187f70543d67ca33","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=51020","https://github.com/FasterXML/jackson-databind/blob/2.13/release-notes/VERSION-2.x","https://security.gentoo.org/glsa/202210-21","https://github.com/FasterXML/jackson-databind/issues/3627","https://github.com/FasterXML/jackson-databind/commit/cd090979b7ea78c75e4de8a4aed04f7e9fa8deea","https://www.debian.org/security/2022/dsa-5283","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://github.com/FasterXML/jackson-databind/commit/7ba9ac5b87a9d6ac0d2815158ecbeb315ad4dcdc","https://github.com/FasterXML/jackson-databind/commit/0e37a39502439ecbaa1a5b5188387c01bf7f7fa1","https://github.com/FasterXML/jackson-databind/commit/d499f2e7bbc5ebd63af11e1f5cf1989fa323aa45","https://github.com/FasterXML/jackson-databind/commits/jackson-databind-2.4.0-rc1?after=75b97b8519f0d50c62523ad85170d80a197a2c86+174&branch=jackson-databind-2.4.0-rc1&qualified_name=refs%2Ftags%2Fjackson-databind-2.4.0-rc1","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.13.4.1...jackson-databind-2.13.4.2","https://github.com/FasterXML/jackson-databind/commit/2c4a601c626f7790cad9d3c322d244e182838288","https://security.netapp.com/advisory/ntap-20221124-0004"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjjh-jjxp-wpff","description":"Uncontrolled Resource Consumption in Jackson-databind"},"relatedVulnerabilities":[{"id":"CVE-2022-42003","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42003","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42003","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42003","date":"2026-10-08","epss":0.03409,"percentile":0.88545}],"urls":["https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=51020","https://github.com/FasterXML/jackson-databind/commit/d78d00ee7b5245b93103fef3187f70543d67ca33","https://github.com/FasterXML/jackson-databind/issues/3590","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://security.gentoo.org/glsa/202210-21","https://security.netapp.com/advisory/ntap-20221124-0004/","https://www.debian.org/security/2022/dsa-5283"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42003","description":"In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled."}]},{"artifact":{"id":"b4f646c66dd594d4","cpes":["cpe:2.3:a:gzip:gzip:1.6-5ubuntu1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/ubuntu/gzip@1.6-5ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.6-5ubuntu1","language":"","licenses":["sha256:f9ac4a5d7a670e3891881a2cdba5fa2cd625c4d58eae4a7aa372ac00a06803bd"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/gzip.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.6-5ubuntu1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-1271","versionConstraint":"< 1.6-5ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"gzip","version":"1.6-5ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-1271","fix":{"state":"fixed","versions":["1.6-5ubuntu1.2"],"available":[{"date":"2022-04-13","kind":"advisory","version":"1.6-5ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-08","epss":0.0507,"percentile":0.92107}],"risk":2.535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1271"},"relatedVulnerabilities":[{"id":"CVE-2022-1271","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-08","epss":0.0507,"percentile":0.92107}],"urls":["https://access.redhat.com/security/cve/CVE-2022-1271","https://bugzilla.redhat.com/show_bug.cgi?id=2073310","https://git.tukaani.org/?p=xz.git%3Ba=commit%3Bh=69d1b3fc29677af8ade8dc15dba83f0589cb63d6","https://lists.gnu.org/r/bug-gzip/2022-04/msg00011.html","https://security-tracker.debian.org/tracker/CVE-2022-1271","https://security.gentoo.org/glsa/202209-01","https://security.netapp.com/advisory/ntap-20220930-0006/","https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch","https://www.openwall.com/lists/oss-security/2022/04/07/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1271","description":"An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system."}]},{"artifact":{"id":"bde30df0cdd91b38","cpes":["cpe:2.3:a:liblzma5:liblzma5:5.2.2-1.3:*:*:*:*:*:*:*"],"name":"liblzma5","purl":"pkg:deb/ubuntu/liblzma5@5.2.2-1.3?arch=amd64&distro=ubuntu-18.04&upstream=xz-utils","type":"deb","version":"5.2.2-1.3","language":"","licenses":["Autoconf","GPL-2","GPL-2+","GPL-3","LGPL-2","LGPL-2.1","LGPL-2.1+","PD","PD-debian","config-h","noderivs","permissive-fsf","permissive-nowarranty","probably-PD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblzma5/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/liblzma5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"xz-utils"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.2.2-1.3ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-1271","versionConstraint":"< 5.2.2-1.3ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"xz-utils","version":"5.2.2-1.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-1271","fix":{"state":"fixed","versions":["5.2.2-1.3ubuntu0.1"],"available":[{"date":"2022-04-13","kind":"advisory","version":"5.2.2-1.3ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-08","epss":0.0507,"percentile":0.92107}],"risk":2.535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1271"},"relatedVulnerabilities":[{"id":"CVE-2022-1271","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1271","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-1271","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1271","date":"2026-10-08","epss":0.0507,"percentile":0.92107}],"urls":["https://access.redhat.com/security/cve/CVE-2022-1271","https://bugzilla.redhat.com/show_bug.cgi?id=2073310","https://git.tukaani.org/?p=xz.git%3Ba=commit%3Bh=69d1b3fc29677af8ade8dc15dba83f0589cb63d6","https://lists.gnu.org/r/bug-gzip/2022-04/msg00011.html","https://security-tracker.debian.org/tracker/CVE-2022-1271","https://security.gentoo.org/glsa/202209-01","https://security.netapp.com/advisory/ntap-20220930-0006/","https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch","https://www.openwall.com/lists/oss-security/2022/04/07/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1271","description":"An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-48565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-48565","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"risk":2.5325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-48565"},"relatedVulnerabilities":[{"id":"CVE-2022-48565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"urls":["https://bugs.python.org/issue42051","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/","https://security.netapp.com/advisory/ntap-20231006-0007/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-48565","description":"An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-48565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-48565","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"risk":2.5325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-48565"},"relatedVulnerabilities":[{"id":"CVE-2022-48565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"urls":["https://bugs.python.org/issue42051","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/","https://security.netapp.com/advisory/ntap-20231006-0007/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-48565","description":"An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-48565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-48565","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"risk":2.5325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-48565"},"relatedVulnerabilities":[{"id":"CVE-2022-48565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"urls":["https://bugs.python.org/issue42051","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/","https://security.netapp.com/advisory/ntap-20231006-0007/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-48565","description":"An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-48565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-48565","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"risk":2.5325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-48565"},"relatedVulnerabilities":[{"id":"CVE-2022-48565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-48565","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-48565","date":"2026-10-08","epss":0.05065,"percentile":0.92102}],"urls":["https://bugs.python.org/issue42051","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/","https://security.netapp.com/advisory/ntap-20231006-0007/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-48565","description":"An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-27619","versionConstraint":"< 3.6.9-1~18.04ubuntu1.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-27619","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.4"],"available":[{"date":"2021-02-25","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.4"}]},"cvss":[],"epss":[{"cve":"CVE-2020-27619","date":"2026-10-08","epss":0.08334,"percentile":0.9482}],"risk":2.5002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-27619"},"relatedVulnerabilities":[{"id":"CVE-2020-27619","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-27619","date":"2026-10-08","epss":0.08334,"percentile":0.9482}],"urls":["https://bugs.python.org/issue41944","https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8","https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9","https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33","https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794","https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad39374b","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://security.gentoo.org/glsa/202402-04","https://security.netapp.com/advisory/ntap-20201123-0004/","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-27619","description":"In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-27619","versionConstraint":"< 3.6.9-1~18.04ubuntu1.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-27619","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.4"],"available":[{"date":"2021-02-25","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.4"}]},"cvss":[],"epss":[{"cve":"CVE-2020-27619","date":"2026-10-08","epss":0.08334,"percentile":0.9482}],"risk":2.5002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-27619"},"relatedVulnerabilities":[{"id":"CVE-2020-27619","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-27619","date":"2026-10-08","epss":0.08334,"percentile":0.9482}],"urls":["https://bugs.python.org/issue41944","https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8","https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9","https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33","https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794","https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad39374b","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://security.gentoo.org/glsa/202402-04","https://security.netapp.com/advisory/ntap-20201123-0004/","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-27619","description":"In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-27619","versionConstraint":"< 3.6.9-1~18.04ubuntu1.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-27619","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.4"],"available":[{"date":"2021-02-25","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.4"}]},"cvss":[],"epss":[{"cve":"CVE-2020-27619","date":"2026-10-08","epss":0.08334,"percentile":0.9482}],"risk":2.5002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-27619"},"relatedVulnerabilities":[{"id":"CVE-2020-27619","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-27619","date":"2026-10-08","epss":0.08334,"percentile":0.9482}],"urls":["https://bugs.python.org/issue41944","https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8","https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9","https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33","https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794","https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad39374b","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://security.gentoo.org/glsa/202402-04","https://security.netapp.com/advisory/ntap-20201123-0004/","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-27619","description":"In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-27619","versionConstraint":"< 3.6.9-1~18.04ubuntu1.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-27619","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.4"],"available":[{"date":"2021-02-25","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.4"}]},"cvss":[],"epss":[{"cve":"CVE-2020-27619","date":"2026-10-08","epss":0.08334,"percentile":0.9482}],"risk":2.5002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-27619"},"relatedVulnerabilities":[{"id":"CVE-2020-27619","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-27619","date":"2026-10-08","epss":0.08334,"percentile":0.9482}],"urls":["https://bugs.python.org/issue41944","https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8","https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9","https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33","https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794","https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad39374b","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/","https://security.gentoo.org/glsa/202402-04","https://security.netapp.com/advisory/ntap-20201123-0004/","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-27619","description":"In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP."}]},{"artifact":{"id":"ec3ebe2590893812","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.9.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.9.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"java-archive","version":"2.9.8","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"11283f21cc480aa86c4df7a0a3243ec508372ed2","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/jackson-databind-2.9.8.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-95cm-88f5-f2c7","versionConstraint":">=2.9.0,<=2.9.10.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.9.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-95cm-88f5-f2c7","fix":{"state":"fixed","versions":["2.9.10.4"],"available":[{"date":"2021-03-30","kind":"first-observed","version":"2.9.10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10672","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10672","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10672","date":"2026-10-08","epss":0.03059,"percentile":0.87211}],"risk":2.493085,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10672","https://github.com/FasterXML/jackson-databind/issues/2659","https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/592872f4235c7f2a3280725278da55544032f72d","https://security.netapp.com/advisory/ntap-20200403-0002","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-95cm-88f5-f2c7","description":"jackson-databind mishandles the interaction between serialization gadgets and typing"},"relatedVulnerabilities":[{"id":"CVE-2020-10672","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10672","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-10672","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-10672","date":"2026-10-08","epss":0.03059,"percentile":0.87211}],"urls":["https://github.com/FasterXML/jackson-databind/issues/2659","https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10672","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms)."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.14"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-22925","versionConstraint":"< 7.58.0-2ubuntu3.14 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22925","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.14"],"available":[{"date":"2021-07-22","kind":"advisory","version":"7.58.0-2ubuntu3.14"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22925","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22925","cwe":"CWE-908","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22925","date":"2026-10-08","epss":0.04929,"percentile":0.91913}],"risk":2.4645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22925"},"relatedVulnerabilities":[{"id":"CVE-2021-22925","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22925","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22925","cwe":"CWE-908","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22925","date":"2026-10-08","epss":0.04929,"percentile":0.91913}],"urls":["http://seclists.org/fulldisclosure/2021/Sep/39","http://seclists.org/fulldisclosure/2021/Sep/40","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://hackerone.com/reports/1223882","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20210902-0003/","https://support.apple.com/kb/HT212804","https://support.apple.com/kb/HT212805","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22925","description":"curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.14"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-22925","versionConstraint":"< 7.58.0-2ubuntu3.14 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22925","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.14"],"available":[{"date":"2021-07-22","kind":"advisory","version":"7.58.0-2ubuntu3.14"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22925","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22925","cwe":"CWE-908","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22925","date":"2026-10-08","epss":0.04929,"percentile":0.91913}],"risk":2.4645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22925"},"relatedVulnerabilities":[{"id":"CVE-2021-22925","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22925","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22925","cwe":"CWE-908","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22925","date":"2026-10-08","epss":0.04929,"percentile":0.91913}],"urls":["http://seclists.org/fulldisclosure/2021/Sep/39","http://seclists.org/fulldisclosure/2021/Sep/40","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://hackerone.com/reports/1223882","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20210902-0003/","https://support.apple.com/kb/HT212804","https://support.apple.com/kb/HT212805","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22925","description":"curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.20"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-2097","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.20 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-2097","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.20"],"available":[{"date":"2022-07-05","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.20"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-2097","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2097","date":"2026-10-08","epss":0.04899,"percentile":0.91868}],"risk":2.4495,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-2097"},"relatedVulnerabilities":[{"id":"CVE-2022-2097","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2097","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2097","date":"2026-10-08","epss":0.04899,"percentile":0.91868}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=919925673d6c9cfed3c1085497f5dfbbed5fc431","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a98f339ddd7e8f487d6e0088d4a9a42324885a93","https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220715-0011/","https://security.netapp.com/advisory/ntap-20230420-0008/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2023/dsa-5343","https://www.openssl.org/news/secadv/20220705.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-2097","description":"AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of \"in place\" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.20"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-2097","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.20 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-2097","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.20"],"available":[{"date":"2022-07-05","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.20"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-2097","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2097","date":"2026-10-08","epss":0.04899,"percentile":0.91868}],"risk":2.4495,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-2097"},"relatedVulnerabilities":[{"id":"CVE-2022-2097","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2097","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2097","date":"2026-10-08","epss":0.04899,"percentile":0.91868}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=919925673d6c9cfed3c1085497f5dfbbed5fc431","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a98f339ddd7e8f487d6e0088d4a9a42324885a93","https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/","https://security.gentoo.org/glsa/202210-02","https://security.netapp.com/advisory/ntap-20220715-0011/","https://security.netapp.com/advisory/ntap-20230420-0008/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2023/dsa-5343","https://www.openssl.org/news/secadv/20220705.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-2097","description":"AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of \"in place\" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30761","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2025-30761","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-30761","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-30761","date":"2026-10-08","epss":0.04873,"percentile":0.91827}],"risk":2.4365,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-30761"},"relatedVulnerabilities":[{"id":"CVE-2025-30761","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30761","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-30761","date":"2026-10-08","epss":0.04873,"percentile":0.91827}],"urls":["https://www.oracle.com/security-alerts/cpujul2025.html","http://www.openwall.com/lists/oss-security/2025/07/16/1","http://www.openwall.com/lists/oss-security/2025/07/21/3","http://www.openwall.com/lists/oss-security/2025/07/24/1","https://lists.debian.org/debian-lts-announce/2025/07/msg00011.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30761","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting).  Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf and  11.0.27; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-22822","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-22822","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-22822","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22822","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22822","date":"2026-10-08","epss":0.04829,"percentile":0.9176}],"risk":2.4145,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-22822"},"relatedVulnerabilities":[{"id":"CVE-2022-22822","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22822","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22822","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22822","date":"2026-10-08","epss":0.04829,"percentile":0.9176}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/539","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22822","description":"addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-25315","versionConstraint":"< 2.2.5-3ubuntu0.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-25315","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.7"],"available":[{"date":"2022-03-10","kind":"advisory","version":"2.2.5-3ubuntu0.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-25315","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25315","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25315","date":"2026-10-08","epss":0.04821,"percentile":0.91746}],"risk":2.4105000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-25315"},"relatedVulnerabilities":[{"id":"CVE-2022-25315","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25315","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25315","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25315","date":"2026-10-08","epss":0.04821,"percentile":0.91746}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/19/1","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/559","https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220303-0008/","https://www.debian.org/security/2022/dsa-5085","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25315","description":"In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames."}]},{"artifact":{"id":"7a6dcfb98884d7c9","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1ubuntu0.3?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1ubuntu0.3","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19603","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19603","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-19603","date":"2026-10-08","epss":0.0803,"percentile":0.94645}],"risk":2.409,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19603"},"relatedVulnerabilities":[{"id":"CVE-2019-19603","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-19603","date":"2026-10-08","epss":0.0803,"percentile":0.94645}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://github.com/sqlite/sqlite/commit/527cbd4a104cb93bf3994b3dd3619a6299a78b13","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E","https://security.netapp.com/advisory/ntap-20191223-0001/","https://usn.ubuntu.com/4394-1/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.sqlite.org/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19603","description":"SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash."}]},{"artifact":{"id":"7a6dcfb98884d7c9","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.22.0-1ubuntu0.3:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/ubuntu/libsqlite3-0@3.22.0-1ubuntu0.3?arch=amd64&distro=ubuntu-18.04&upstream=sqlite3","type":"deb","version":"3.22.0-1ubuntu0.3","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.22.0-1ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-8740","versionConstraint":"< 3.22.0-1ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"sqlite3","version":"3.22.0-1ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-8740","fix":{"state":"fixed","versions":["3.22.0-1ubuntu0.4"],"available":[{"date":"2020-06-10","kind":"advisory","version":"3.22.0-1ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-8740","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-8740","date":"2026-10-08","epss":0.07966,"percentile":0.94609}],"risk":2.3897999999999997,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-8740"},"relatedVulnerabilities":[{"id":"CVE-2018-8740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-8740","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-8740","date":"2026-10-08","epss":0.07966,"percentile":0.94609}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00050.html","http://www.securityfocus.com/bid/103466","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=6964","https://bugs.launchpad.net/ubuntu/+source/sqlite3/+bug/1756349","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/01/msg00009.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PU4NZ6DDU4BEM3ACM3FM6GLEPX56ZQXK/","https://usn.ubuntu.com/4205-1/","https://usn.ubuntu.com/4394-1/","https://www.sqlite.org/cgi/src/timeline?r=corrupt-schema","https://www.sqlite.org/cgi/src/vdiff?from=1774f1c3baf0bc3d&to=d75e67654aa9620b"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-8740","description":"In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, related to build.c and prepare.c."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-25314","versionConstraint":"< 2.2.5-3ubuntu0.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-25314","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.7"],"available":[{"date":"2022-03-10","kind":"advisory","version":"2.2.5-3ubuntu0.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-25314","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25314","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25314","date":"2026-10-08","epss":0.04693,"percentile":0.91557}],"risk":2.3465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-25314"},"relatedVulnerabilities":[{"id":"CVE-2022-25314","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25314","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25314","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25314","date":"2026-10-08","epss":0.04693,"percentile":0.91557}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/19/1","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/560","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220303-0008/","https://www.debian.org/security/2022/dsa-5085","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25314","description":"In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-32221","versionConstraint":"< 7.58.0-2ubuntu3.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32221","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.21"],"available":[{"date":"2022-10-26","kind":"advisory","version":"7.58.0-2ubuntu3.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32221","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32221","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32221","date":"2026-10-08","epss":0.04676,"percentile":0.91537}],"risk":2.338,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32221"},"relatedVulnerabilities":[{"id":"CVE-2022-32221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32221","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32221","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32221","date":"2026-10-08","epss":0.04676,"percentile":0.91537}],"urls":["http://seclists.org/fulldisclosure/2023/Jan/19","http://seclists.org/fulldisclosure/2023/Jan/20","http://www.openwall.com/lists/oss-security/2023/05/17/4","https://hackerone.com/reports/1704017","https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20230110-0006/","https://security.netapp.com/advisory/ntap-20230208-0002/","https://support.apple.com/kb/HT213604","https://support.apple.com/kb/HT213605","https://www.debian.org/security/2023/dsa-5330"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32221","description":"When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-32221","versionConstraint":"< 7.58.0-2ubuntu3.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-32221","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.21"],"available":[{"date":"2022-10-26","kind":"advisory","version":"7.58.0-2ubuntu3.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-32221","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32221","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32221","date":"2026-10-08","epss":0.04676,"percentile":0.91537}],"risk":2.338,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-32221"},"relatedVulnerabilities":[{"id":"CVE-2022-32221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32221","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-32221","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32221","date":"2026-10-08","epss":0.04676,"percentile":0.91537}],"urls":["http://seclists.org/fulldisclosure/2023/Jan/19","http://seclists.org/fulldisclosure/2023/Jan/20","http://www.openwall.com/lists/oss-security/2023/05/17/4","https://hackerone.com/reports/1704017","https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20230110-0006/","https://security.netapp.com/advisory/ntap-20230208-0002/","https://support.apple.com/kb/HT213604","https://support.apple.com/kb/HT213605","https://www.debian.org/security/2023/dsa-5330"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32221","description":"When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3733","versionConstraint":"< 3.6.9-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3733","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.6"],"available":[{"date":"2021-12-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3733","date":"2026-10-08","epss":0.04675,"percentile":0.91534}],"risk":2.3375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3733"},"relatedVulnerabilities":[{"id":"CVE-2021-3733","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3733","date":"2026-10-08","epss":0.04675,"percentile":0.91534}],"urls":["https://bugs.python.org/issue43075","https://bugzilla.redhat.com/show_bug.cgi?id=1995234","https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb","https://github.com/python/cpython/pull/24391","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://security.netapp.com/advisory/ntap-20220407-0001/","https://ubuntu.com/security/CVE-2021-3733","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3733","description":"There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3733","versionConstraint":"< 3.6.9-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3733","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.6"],"available":[{"date":"2021-12-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3733","date":"2026-10-08","epss":0.04675,"percentile":0.91534}],"risk":2.3375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3733"},"relatedVulnerabilities":[{"id":"CVE-2021-3733","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3733","date":"2026-10-08","epss":0.04675,"percentile":0.91534}],"urls":["https://bugs.python.org/issue43075","https://bugzilla.redhat.com/show_bug.cgi?id=1995234","https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb","https://github.com/python/cpython/pull/24391","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://security.netapp.com/advisory/ntap-20220407-0001/","https://ubuntu.com/security/CVE-2021-3733","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3733","description":"There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3733","versionConstraint":"< 3.6.9-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3733","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.6"],"available":[{"date":"2021-12-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3733","date":"2026-10-08","epss":0.04675,"percentile":0.91534}],"risk":2.3375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3733"},"relatedVulnerabilities":[{"id":"CVE-2021-3733","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3733","date":"2026-10-08","epss":0.04675,"percentile":0.91534}],"urls":["https://bugs.python.org/issue43075","https://bugzilla.redhat.com/show_bug.cgi?id=1995234","https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb","https://github.com/python/cpython/pull/24391","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://security.netapp.com/advisory/ntap-20220407-0001/","https://ubuntu.com/security/CVE-2021-3733","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3733","description":"There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3733","versionConstraint":"< 3.6.9-1~18.04ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3733","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.6"],"available":[{"date":"2021-12-17","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3733","date":"2026-10-08","epss":0.04675,"percentile":0.91534}],"risk":2.3375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3733"},"relatedVulnerabilities":[{"id":"CVE-2021-3733","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3733","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3733","date":"2026-10-08","epss":0.04675,"percentile":0.91534}],"urls":["https://bugs.python.org/issue43075","https://bugzilla.redhat.com/show_bug.cgi?id=1995234","https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb","https://github.com/python/cpython/pull/24391","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://security.netapp.com/advisory/ntap-20220407-0001/","https://ubuntu.com/security/CVE-2021-3733","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3733","description":"There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-8286","versionConstraint":"< 7.58.0-2ubuntu3.12 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8286","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.12"],"available":[{"date":"2020-12-09","kind":"advisory","version":"7.58.0-2ubuntu3.12"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8286","date":"2026-10-08","epss":0.04631,"percentile":0.9147}],"risk":2.3154999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8286"},"relatedVulnerabilities":[{"id":"CVE-2020-8286","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8286","date":"2026-10-08","epss":0.04631,"percentile":0.9147}],"urls":["http://seclists.org/fulldisclosure/2021/Apr/50","http://seclists.org/fulldisclosure/2021/Apr/51","http://seclists.org/fulldisclosure/2021/Apr/54","https://cert-portal.siemens.com/productcert/pdf/ssa-200951.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2020-8286.html","https://hackerone.com/reports/1048457","https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/","https://security.gentoo.org/glsa/202012-14","https://security.netapp.com/advisory/ntap-20210122-0007/","https://support.apple.com/kb/HT212325","https://support.apple.com/kb/HT212326","https://support.apple.com/kb/HT212327","https://www.debian.org/security/2021/dsa-4881","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8286","description":"curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.12"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-8286","versionConstraint":"< 7.58.0-2ubuntu3.12 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8286","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.12"],"available":[{"date":"2020-12-09","kind":"advisory","version":"7.58.0-2ubuntu3.12"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8286","date":"2026-10-08","epss":0.04631,"percentile":0.9147}],"risk":2.3154999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8286"},"relatedVulnerabilities":[{"id":"CVE-2020-8286","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2020-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8286","date":"2026-10-08","epss":0.04631,"percentile":0.9147}],"urls":["http://seclists.org/fulldisclosure/2021/Apr/50","http://seclists.org/fulldisclosure/2021/Apr/51","http://seclists.org/fulldisclosure/2021/Apr/54","https://cert-portal.siemens.com/productcert/pdf/ssa-200951.pdf","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2020-8286.html","https://hackerone.com/reports/1048457","https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/","https://security.gentoo.org/glsa/202012-14","https://security.netapp.com/advisory/ntap-20210122-0007/","https://support.apple.com/kb/HT212325","https://support.apple.com/kb/HT212326","https://support.apple.com/kb/HT212327","https://www.debian.org/security/2021/dsa-4881","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8286","description":"curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23852","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23852","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23852","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23852","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23852","date":"2026-10-08","epss":0.04563,"percentile":0.9136}],"risk":2.2815,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23852"},"relatedVulnerabilities":[{"id":"CVE-2022-23852","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23852","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23852","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23852","date":"2026-10-08","epss":0.04563,"percentile":0.9136}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/550","https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220217-0001/","https://www.debian.org/security/2022/dsa-5073","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.tenable.com/security/tns-2022-05"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23852","description":"Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-22946","versionConstraint":"< 7.58.0-2ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22946","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.15"],"available":[{"date":"2021-09-15","kind":"advisory","version":"7.58.0-2ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22946","cwe":"CWE-325","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-22946","date":"2026-10-08","epss":0.04539,"percentile":0.91321}],"risk":2.2695,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22946"},"relatedVulnerabilities":[{"id":"CVE-2021-22946","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22946","cwe":"CWE-325","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-22946","date":"2026-10-08","epss":0.04539,"percentile":0.91321}],"urls":["http://seclists.org/fulldisclosure/2022/Mar/29","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://hackerone.com/reports/1334111","https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20211029-0003/","https://security.netapp.com/advisory/ntap-20220121-0008/","https://support.apple.com/kb/HT213183","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22946","description":"A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-22946","versionConstraint":"< 7.58.0-2ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22946","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.15"],"available":[{"date":"2021-09-15","kind":"advisory","version":"7.58.0-2ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22946","cwe":"CWE-325","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-22946","date":"2026-10-08","epss":0.04539,"percentile":0.91321}],"risk":2.2695,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22946"},"relatedVulnerabilities":[{"id":"CVE-2021-22946","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22946","cwe":"CWE-325","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-22946","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-22946","date":"2026-10-08","epss":0.04539,"percentile":0.91321}],"urls":["http://seclists.org/fulldisclosure/2022/Mar/29","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://hackerone.com/reports/1334111","https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20211029-0003/","https://security.netapp.com/advisory/ntap-20220121-0008/","https://support.apple.com/kb/HT213183","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22946","description":"A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-0215","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-0215","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0215","date":"2026-10-08","epss":0.04494,"percentile":0.91248}],"risk":2.247,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-0215"},"relatedVulnerabilities":[{"id":"CVE-2023-0215","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0215","date":"2026-10-08","epss":0.04494,"percentile":0.91248}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8818064ce3c3c0f1b740a5aaba2a987e75bfbafd","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9816136fe31d92ace4037d5da5257f763aeeb4eb","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=c3829dd8825c654652201e16f8a0a0c46ee3f344","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230427-0007/","https://security.netapp.com/advisory/ntap-20230427-0009/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0215","description":"The public API function BIO_new_NDEF is a helper function used for streaming\nASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the\nSMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by\nend user applications.\n\nThe function receives a BIO from the caller, prepends a new BIO_f_asn1 filter\nBIO onto the front of it to form a BIO chain, and then returns the new head of\nthe BIO chain to the caller. Under certain conditions, for example if a CMS\nrecipient public key is invalid, the new filter BIO is freed and the function\nreturns a NULL result indicating a failure. However, in this case, the BIO chain\nis not properly cleaned up and the BIO passed by the caller still retains\ninternal pointers to the previously freed filter BIO. If the caller then goes on\nto call BIO_pop() on the BIO then a use-after-free will occur. This will most\nlikely result in a crash.\n\n\n\nThis scenario occurs directly in the internal function B64_write_ASN1() which\nmay cause BIO_new_NDEF() to be called and will subsequently call BIO_pop() on\nthe BIO. This internal function is in turn called by the public API functions\nPEM_write_bio_ASN1_stream, PEM_write_bio_CMS_stream, PEM_write_bio_PKCS7_stream,\nSMIME_write_ASN1, SMIME_write_CMS and SMIME_write_PKCS7.\n\nOther public API functions that may be impacted by this include\ni2d_ASN1_bio_stream, BIO_new_CMS, BIO_new_PKCS7, i2d_CMS_bio_stream and\ni2d_PKCS7_bio_stream.\n\nThe OpenSSL cms and smime command line applications are similarly affected."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-0215","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.21 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-0215","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.21"],"available":[{"date":"2023-02-07","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.21"}]},"cvss":[],"cwes":[{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0215","date":"2026-10-08","epss":0.04494,"percentile":0.91248}],"risk":2.247,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-0215"},"relatedVulnerabilities":[{"id":"CVE-2023-0215","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0215","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0215","date":"2026-10-08","epss":0.04494,"percentile":0.91248}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8818064ce3c3c0f1b740a5aaba2a987e75bfbafd","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9816136fe31d92ace4037d5da5257f763aeeb4eb","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=c3829dd8825c654652201e16f8a0a0c46ee3f344","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230427-0007/","https://security.netapp.com/advisory/ntap-20230427-0009/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.openssl.org/news/secadv/20230207.txt","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0215","description":"The public API function BIO_new_NDEF is a helper function used for streaming\nASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the\nSMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by\nend user applications.\n\nThe function receives a BIO from the caller, prepends a new BIO_f_asn1 filter\nBIO onto the front of it to form a BIO chain, and then returns the new head of\nthe BIO chain to the caller. Under certain conditions, for example if a CMS\nrecipient public key is invalid, the new filter BIO is freed and the function\nreturns a NULL result indicating a failure. However, in this case, the BIO chain\nis not properly cleaned up and the BIO passed by the caller still retains\ninternal pointers to the previously freed filter BIO. If the caller then goes on\nto call BIO_pop() on the BIO then a use-after-free will occur. This will most\nlikely result in a crash.\n\n\n\nThis scenario occurs directly in the internal function B64_write_ASN1() which\nmay cause BIO_new_NDEF() to be called and will subsequently call BIO_pop() on\nthe BIO. This internal function is in turn called by the public API functions\nPEM_write_bio_ASN1_stream, PEM_write_bio_CMS_stream, PEM_write_bio_PKCS7_stream,\nSMIME_write_ASN1, SMIME_write_CMS and SMIME_write_PKCS7.\n\nOther public API functions that may be impacted by this include\ni2d_ASN1_bio_stream, BIO_new_CMS, BIO_new_PKCS7, i2d_CMS_bio_stream and\ni2d_PKCS7_bio_stream.\n\nThe OpenSSL cms and smime command line applications are similarly affected."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-12243","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-12243","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.5"],"available":[{"date":"2020-05-06","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-12243","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12243","date":"2026-10-08","epss":0.04423,"percentile":0.91112}],"risk":2.2115,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-12243"},"relatedVulnerabilities":[{"id":"CVE-2020-12243","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-12243","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12243","date":"2026-10-08","epss":0.04423,"percentile":0.91112}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00016.html","https://bugs.openldap.org/show_bug.cgi?id=9202","https://git.openldap.org/openldap/openldap/-/blob/OPENLDAP_REL_ENG_2_4/CHANGES","https://git.openldap.org/openldap/openldap/-/commit/98464c11df8247d6a11b52e294ba5dd4f0380440","https://lists.debian.org/debian-lts-announce/2020/05/msg00001.html","https://security.netapp.com/advisory/ntap-20200511-0003/","https://support.apple.com/kb/HT211289","https://usn.ubuntu.com/4352-1/","https://usn.ubuntu.com/4352-2/","https://www.debian.org/security/2020/dsa-4666","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-12243","description":"In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash)."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-12243","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-12243","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.5"],"available":[{"date":"2020-05-06","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-12243","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12243","date":"2026-10-08","epss":0.04423,"percentile":0.91112}],"risk":2.2115,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-12243"},"relatedVulnerabilities":[{"id":"CVE-2020-12243","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-12243","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12243","date":"2026-10-08","epss":0.04423,"percentile":0.91112}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00016.html","https://bugs.openldap.org/show_bug.cgi?id=9202","https://git.openldap.org/openldap/openldap/-/blob/OPENLDAP_REL_ENG_2_4/CHANGES","https://git.openldap.org/openldap/openldap/-/commit/98464c11df8247d6a11b52e294ba5dd4f0380440","https://lists.debian.org/debian-lts-announce/2020/05/msg00001.html","https://security.netapp.com/advisory/ntap-20200511-0003/","https://support.apple.com/kb/HT211289","https://usn.ubuntu.com/4352-1/","https://usn.ubuntu.com/4352-2/","https://www.debian.org/security/2020/dsa-4666","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-12243","description":"In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash)."}]},{"artifact":{"id":"3445236446ec4939","cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"krb5-locales","purl":"pkg:deb/ubuntu/krb5-locales@1.16-2ubuntu0.1?arch=all&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-28196","versionConstraint":"< 1.16-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-28196","fix":{"state":"fixed","versions":["1.16-2ubuntu0.2"],"available":[{"date":"2020-11-17","kind":"advisory","version":"1.16-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"risk":2.2085,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-28196"},"relatedVulnerabilities":[{"id":"CVE-2020-28196","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"urls":["https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfd","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/11/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/","https://security.gentoo.org/glsa/202011-17","https://security.netapp.com/advisory/ntap-20201202-0001/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://www.debian.org/security/2020/dsa-4795","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-28196","description":"MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit."}]},{"artifact":{"id":"f3fc35a2cb3401bd","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/ubuntu/libgssapi-krb5-2@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-28196","versionConstraint":"< 1.16-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-28196","fix":{"state":"fixed","versions":["1.16-2ubuntu0.2"],"available":[{"date":"2020-11-17","kind":"advisory","version":"1.16-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"risk":2.2085,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-28196"},"relatedVulnerabilities":[{"id":"CVE-2020-28196","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"urls":["https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfd","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/11/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/","https://security.gentoo.org/glsa/202011-17","https://security.netapp.com/advisory/ntap-20201202-0001/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://www.debian.org/security/2020/dsa-4795","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-28196","description":"MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit."}]},{"artifact":{"id":"ce64c2275844a0e2","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/ubuntu/libk5crypto3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-28196","versionConstraint":"< 1.16-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-28196","fix":{"state":"fixed","versions":["1.16-2ubuntu0.2"],"available":[{"date":"2020-11-17","kind":"advisory","version":"1.16-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"risk":2.2085,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-28196"},"relatedVulnerabilities":[{"id":"CVE-2020-28196","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"urls":["https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfd","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/11/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/","https://security.gentoo.org/glsa/202011-17","https://security.netapp.com/advisory/ntap-20201202-0001/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://www.debian.org/security/2020/dsa-4795","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-28196","description":"MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit."}]},{"artifact":{"id":"a0e77fe46f00e692","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/ubuntu/libkrb5-3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-28196","versionConstraint":"< 1.16-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-28196","fix":{"state":"fixed","versions":["1.16-2ubuntu0.2"],"available":[{"date":"2020-11-17","kind":"advisory","version":"1.16-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"risk":2.2085,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-28196"},"relatedVulnerabilities":[{"id":"CVE-2020-28196","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"urls":["https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfd","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/11/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/","https://security.gentoo.org/glsa/202011-17","https://security.netapp.com/advisory/ntap-20201202-0001/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://www.debian.org/security/2020/dsa-4795","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-28196","description":"MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit."}]},{"artifact":{"id":"402827dd4cb6593f","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/ubuntu/libkrb5support0@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.16-2ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-28196","versionConstraint":"< 1.16-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-28196","fix":{"state":"fixed","versions":["1.16-2ubuntu0.2"],"available":[{"date":"2020-11-17","kind":"advisory","version":"1.16-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"risk":2.2085,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-28196"},"relatedVulnerabilities":[{"id":"CVE-2020-28196","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-28196","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-28196","date":"2026-10-08","epss":0.04417,"percentile":0.91102}],"urls":["https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfd","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/11/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/","https://security.gentoo.org/glsa/202011-17","https://security.netapp.com/advisory/ntap-20201202-0001/","https://security.netapp.com/advisory/ntap-20210513-0002/","https://www.debian.org/security/2020/dsa-4795","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-28196","description":"MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35603","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35603","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35603","date":"2026-10-08","epss":0.04411,"percentile":0.91088}],"risk":2.2055000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35603"},"relatedVulnerabilities":[{"id":"CVE-2021-35603","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35603","date":"2026-10-08","epss":0.04411,"percentile":0.91088}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35603","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"5d52c6da56f9d4a6","cpes":["cpe:2.3:a:org.hibernate.orm.core:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.orm.core:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-core:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-core:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_core:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_core:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-org:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-org:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_org:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_org:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.orm.core:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.orm.core:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:core:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:core:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-core:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_core:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-core:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-org:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_core:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_org:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:orm:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:orm:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-org:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_org:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:core:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:core:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:orm:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:orm:orm:5.4.6.Final:*:*:*:*:*:*:*"],"name":"hibernate-core","purl":"pkg:maven/org.hibernate/hibernate-core@5.4.6.Final","type":"java-archive","version":"5.4.6.Final","language":"java","licenses":[],"metadata":{"pomGroupID":"org.hibernate","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/hibernate-core-5.4.6.Final.jar","manifestName":"","pomArtifactID":"hibernate-core","archiveDigests":[{"value":"a319fdf00595c7e29fba31ef23b4a58fbe333f47","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/hibernate-core-5.4.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.24.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j8jw-g6fq-mp7h","versionConstraint":">=5.4.0.Final,<5.4.24.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.hibernate:hibernate-core","version":"5.4.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j8jw-g6fq-mp7h","fix":{"state":"fixed","versions":["5.4.24.Final"],"available":[{"date":"2022-02-10","kind":"first-observed","version":"5.4.24.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25638","cwe":"CWE-89","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-25638","cwe":"CWE-89","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25638","date":"2026-10-08","epss":0.02929,"percentile":0.86672}],"risk":2.182105,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-25638","https://bugzilla.redhat.com/show_bug.cgi?id=1881353","https://lists.debian.org/debian-lts-announce/2021/01/msg00000.html","https://www.debian.org/security/2021/dsa-4908","https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44@%3Cdev.turbine.apache.org%3E","https://lists.apache.org/thread.html/rf2378209c676a28b71f9b604a3b3517c448540b85367160e558ef9df@%3Ccommits.turbine.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/hibernate/hibernate-orm/commit/36ebf7d3836e83e99f2a91777b5389e1daf1f2b7","https://github.com/hibernate/hibernate-orm/commit/59fede7acaaa1579b561407aefa582311f7ebe78","https://github.com/hibernate/hibernate-orm/commit/d22bbb5c339c9df7712c3365bb1df97c91b35ec5"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j8jw-g6fq-mp7h","description":"SQL injection in hibernate-core"},"relatedVulnerabilities":[{"id":"CVE-2020-25638","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25638","cwe":"CWE-89","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-25638","cwe":"CWE-89","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25638","date":"2026-10-08","epss":0.02929,"percentile":0.86672}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1881353","https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44%40%3Cdev.turbine.apache.org%3E","https://lists.apache.org/thread.html/rf2378209c676a28b71f9b604a3b3517c448540b85367160e558ef9df%40%3Ccommits.turbine.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/01/msg00000.html","https://www.debian.org/security/2021/dsa-4908","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25638","description":"A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14621","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14621","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14621","date":"2026-10-08","epss":0.0435,"percentile":0.90973}],"risk":2.175,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14621"},"relatedVulnerabilities":[{"id":"CVE-2020-14621","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14621","date":"2026-10-08","epss":0.0435,"percentile":0.90973}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14621","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"958287065b0f2a45","cpes":["cpe:2.3:a:org.h2.util.DbDriverActivator:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:DbDriverActivator:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:org.h2.util.DbDriverActivator:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:com.h2database:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:org.h2.util.DbDriverActivator:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2database:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:DbDriverActivator:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:util:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:DbDriverActivator:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2:DbDriverActivator:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:com.h2database:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:com.h2database:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2database:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2database:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:util:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2:util:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:util:h2:1.4.200:*:*:*:*:*:*:*","cpe:2.3:a:h2:h2:1.4.200:*:*:*:*:*:*:*"],"name":"h2","purl":"pkg:maven/com.h2database/h2@1.4.200","type":"java-archive","version":"1.4.200","language":"java","licenses":["https://h2database.com/html/license.html"],"metadata":{"pomGroupID":"com.h2database","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/h2-1.4.200.jar","manifestName":"","pomArtifactID":"h2","archiveDigests":[{"value":"f7533fe7cb8e99c87a43d325a77b4b678ad9031a","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/h2-1.4.200.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.0.202"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7rpj-hg47-cx62","versionConstraint":">=1.4.198,<2.0.202 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.h2database:h2","version":"1.4.200"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7rpj-hg47-cx62","fix":{"state":"fixed","versions":["2.0.202"],"available":[{"date":"2021-12-17","kind":"first-observed","version":"2.0.202"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23463","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-23463","date":"2026-10-08","epss":0.02787,"percentile":0.85989}],"risk":2.17386,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-23463","https://github.com/h2database/h2database/issues/3195","https://github.com/h2database/h2database/pull/3199","https://github.com/h2database/h2database/commit/d83285fd2e48fb075780ee95badee6f5a15ea7f8%23diff-008c2e4462609982199cd83e7cf6f1d6b41296b516783f6752c44b9f15dc7bc3","https://snyk.io/vuln/SNYK-JAVA-COMH2DATABASE-1769238","https://github.com/h2database/h2database/pull/3199#issuecomment-1002830390","https://github.com/boris-unckel/h2database/commit/f9ad6aef2bfa59eba2b4d3e7c4c32d2cce8e8b05","https://security.netapp.com/advisory/ntap-20230818-0010/","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7rpj-hg47-cx62","description":"Improper Restriction of XML External Entity Reference in com.h2database:h2."},"relatedVulnerabilities":[{"id":"CVE-2021-23463","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:P","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-23463","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-23463","date":"2026-10-08","epss":0.02787,"percentile":0.85989}],"urls":["https://github.com/h2database/h2database/commit/d83285fd2e48fb075780ee95badee6f5a15ea7f8%23diff-008c2e4462609982199cd83e7cf6f1d6b41296b516783f6752c44b9f15dc7bc3","https://github.com/h2database/h2database/issues/3195","https://github.com/h2database/h2database/pull/3199","https://security.netapp.com/advisory/ntap-20230818-0010/","https://snyk.io/vuln/SNYK-JAVA-COMH2DATABASE-1769238","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-23463","description":"The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36225","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36225","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36225","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36225","date":"2026-10-08","epss":0.043,"percentile":0.90884}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36225"},"relatedVulnerabilities":[{"id":"CVE-2020-36225","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36225","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36225","date":"2026-10-08","epss":0.043,"percentile":0.90884}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9412","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36225","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36225","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36225","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36225","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36225","date":"2026-10-08","epss":0.043,"percentile":0.90884}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36225"},"relatedVulnerabilities":[{"id":"CVE-2020-36225","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36225","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36225","date":"2026-10-08","epss":0.043,"percentile":0.90884}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9412","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36225","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36223","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36223","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36223","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36223","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36223","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36223"},"relatedVulnerabilities":[{"id":"CVE-2020-36223","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36223","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36223","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36223","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9408","https://git.openldap.org/openldap/openldap/-/commit/21981053a1195ae1555e23df4d9ac68d34ede9dd","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36223","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read)."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36224","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36224","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36224","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36224","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36224"},"relatedVulnerabilities":[{"id":"CVE-2020-36224","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36224","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36224","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9409","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36224","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36229","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36229","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36229","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36229","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36229"},"relatedVulnerabilities":[{"id":"CVE-2020-36229","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36229","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36229","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9425","https://git.openldap.org/openldap/openldap/-/commit/4bdfffd2889c0c5cdf58bebafbdc8fce4bb2bff0","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36229","description":"A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36223","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36223","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36223","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36223","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36223","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36223"},"relatedVulnerabilities":[{"id":"CVE-2020-36223","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36223","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-36223","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36223","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9408","https://git.openldap.org/openldap/openldap/-/commit/21981053a1195ae1555e23df4d9ac68d34ede9dd","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36223","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read)."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36224","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36224","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36224","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36224","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36224"},"relatedVulnerabilities":[{"id":"CVE-2020-36224","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36224","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36224","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9409","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36224","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36229","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36229","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-36229","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36229","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"risk":2.15,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36229"},"relatedVulnerabilities":[{"id":"CVE-2020-36229","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36229","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-36229","date":"2026-10-08","epss":0.043,"percentile":0.90883}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9425","https://git.openldap.org/openldap/openldap/-/commit/4bdfffd2889c0c5cdf58bebafbdc8fce4bb2bff0","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36229","description":"A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-2341","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-2341","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-2341","date":"2026-10-08","epss":0.04238,"percentile":0.90772}],"risk":2.119,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-2341"},"relatedVulnerabilities":[{"id":"CVE-2021-2341","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-2341","date":"2026-10-08","epss":0.04238,"percentile":0.90772}],"urls":["https://lists.debian.org/debian-lts-announce/2021/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A4TTUHVQF2MGUTP6GTCXLZS4GXK3XUWC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N57OFX5EJKHHDW4WAOBZFWA5CL4VIIK5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PJJ75FHSUZGWPV4UJTSMQHWLOQ77LHTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VTRQIXB52KIXUAO6JBYUKYWXST2NKNAK/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20210723-0002/","https://www.debian.org/security/2021/dsa-4946","https://www.oracle.com/security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-2341","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36226","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36226","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"epss":[{"cve":"CVE-2020-36226","date":"2026-10-08","epss":0.04184,"percentile":0.90665}],"risk":2.092,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36226"},"relatedVulnerabilities":[{"id":"CVE-2020-36226","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-36226","date":"2026-10-08","epss":0.04184,"percentile":0.90665}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9413","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36226","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-36226","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-36226","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.9"],"available":[{"date":"2021-02-08","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.9"}]},"cvss":[],"epss":[{"cve":"CVE-2020-36226","date":"2026-10-08","epss":0.04184,"percentile":0.90665}],"risk":2.092,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-36226"},"relatedVulnerabilities":[{"id":"CVE-2020-36226","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-36226","date":"2026-10-08","epss":0.04184,"percentile":0.90665}],"urls":["http://seclists.org/fulldisclosure/2021/May/64","http://seclists.org/fulldisclosure/2021/May/65","http://seclists.org/fulldisclosure/2021/May/70","https://bugs.openldap.org/show_bug.cgi?id=9413","https://git.openldap.org/openldap/openldap/-/commit/554dff1927176579d652f2fe60c90e9abbad4c65","https://git.openldap.org/openldap/openldap/-/commit/5a2017d4e61a6ddc4dcb4415028e0d08eb6bca26","https://git.openldap.org/openldap/openldap/-/commit/c0b61a9486508e5202aa2e0cfb68c9813731b439","https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8","https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html","https://security.netapp.com/advisory/ntap-20210226-0002/","https://support.apple.com/kb/HT212529","https://support.apple.com/kb/HT212530","https://support.apple.com/kb/HT212531","https://www.debian.org/security/2021/dsa-4845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36226","description":"A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.16+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21540","versionConstraint":"< 11.0.16+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21540","fix":{"state":"fixed","versions":["11.0.16+8-0ubuntu1~18.04"],"available":[{"date":"2022-08-04","kind":"advisory","version":"11.0.16+8-0ubuntu1~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21540","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21540","date":"2026-10-08","epss":0.04167,"percentile":0.90627}],"risk":2.0835,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21540"},"relatedVulnerabilities":[{"id":"CVE-2022-21540","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21540","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21540","date":"2026-10-08","epss":0.04167,"percentile":0.90627}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB/","https://security.gentoo.org/glsa/202401-25","https://security.netapp.com/advisory/ntap-20220729-0009/","https://www.debian.org/security/2022/dsa-5188","https://www.debian.org/security/2022/dsa-5192","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21540","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"2a658e44e9176fca","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.25:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.25","type":"java-archive","version":"1.25","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/snakeyaml-1.25.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"8b6e01ef661d8378ae6dd7b511a7f2a33fae1421","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/snakeyaml-1.25.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3mc7-4q67-w48m","versionConstraint":"<1.31 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.25"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3mc7-4q67-w48m","fix":{"state":"fixed","versions":["1.31"],"available":[{"date":"2022-09-12","kind":"first-observed","version":"1.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25857","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-25857","date":"2026-10-08","epss":0.02749,"percentile":0.85777}],"risk":2.06175,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-25857","https://github.com/snakeyaml/snakeyaml/commit/fc300780da21f4bb92c148bc90257201220cf174","https://bitbucket.org/snakeyaml/snakeyaml/commits/fc300780da21f4bb92c148bc90257201220cf174","https://bitbucket.org/snakeyaml/snakeyaml/issues/525","https://security.snyk.io/vuln/SNYK-JAVA-ORGYAML-2806360","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.netapp.com/advisory/ntap-20240315-0010"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3mc7-4q67-w48m","description":"Uncontrolled Resource Consumption in snakeyaml"},"relatedVulnerabilities":[{"id":"CVE-2022-25857","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25857","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-25857","date":"2026-10-08","epss":0.02749,"percentile":0.85777}],"urls":["https://bitbucket.org/snakeyaml/snakeyaml/commits/fc300780da21f4bb92c148bc90257201220cf174","https://bitbucket.org/snakeyaml/snakeyaml/issues/525","https://github.com/snakeyaml/snakeyaml/commit/fc300780da21f4bb92c148bc90257201220cf174","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.netapp.com/advisory/ntap-20240315-0010/","https://security.snyk.io/vuln/SNYK-JAVA-ORGYAML-2806360"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25857","description":"The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections."}]},{"artifact":{"id":"100fe9e3e8e98cf6","cpes":["cpe:2.3:a:libonig4:libonig4:6.7.0-1:*:*:*:*:*:*:*"],"name":"libonig4","purl":"pkg:deb/ubuntu/libonig4@6.7.0-1?arch=amd64&distro=ubuntu-18.04&upstream=libonig","type":"deb","version":"6.7.0-1","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libonig4/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libonig4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libonig4:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libonig4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libonig"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19203","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libonig","version":"6.7.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19203","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-19203","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19203","date":"2026-10-08","epss":0.04052,"percentile":0.90381}],"risk":2.026,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19203"},"relatedVulnerabilities":[{"id":"CVE-2019-19203","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-19203","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19203","date":"2026-10-08","epss":0.04052,"percentile":0.90381}],"urls":["https://github.com/ManhNDd/CVE-2019-19203","https://github.com/kkos/oniguruma/issues/163","https://github.com/kkos/oniguruma/releases/tag/v6.9.4_rc2","https://github.com/tarantula-team/CVE-2019-19203","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NO267PLHGYZSWX3XTRPKYBKD4J3YOU5V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3MBNW6Z4DOXSCNWGBLQ7OA3OGUJ44WL/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19203","description":"An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read."}]},{"artifact":{"id":"100fe9e3e8e98cf6","cpes":["cpe:2.3:a:libonig4:libonig4:6.7.0-1:*:*:*:*:*:*:*"],"name":"libonig4","purl":"pkg:deb/ubuntu/libonig4@6.7.0-1?arch=amd64&distro=ubuntu-18.04&upstream=libonig","type":"deb","version":"6.7.0-1","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libonig4/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libonig4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libonig4:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libonig4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libonig"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-13224","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libonig","version":"6.7.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-13224","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-13224","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-13224","date":"2026-10-08","epss":0.04047,"percentile":0.90367}],"risk":2.0235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-13224"},"relatedVulnerabilities":[{"id":"CVE-2019-13224","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-13224","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-13224","date":"2026-10-08","epss":0.04047,"percentile":0.90367}],"urls":["https://github.com/kkos/oniguruma/commit/0f7f61ed1b7b697e283e37bd2d731d0bd57adb55","https://lists.debian.org/debian-lts-announce/2019/07/msg00013.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWCPDTZOIUKGMFAD5NAKUB7FPJFAIQN5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNL26OZSQRVLEO6JRNUVIMZTICXBNEQW/","https://security.gentoo.org/glsa/201911-03","https://support.f5.com/csp/article/K00103182","https://support.f5.com/csp/article/K00103182?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4088-1/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-13224","description":"A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onig_new_deluxe(). Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.15+10-0ubuntu0.18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21476","versionConstraint":"< 11.0.15+10-0ubuntu0.18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21476","fix":{"state":"fixed","versions":["11.0.15+10-0ubuntu0.18.04.1"],"available":[{"date":"2022-04-26","kind":"advisory","version":"11.0.15+10-0ubuntu0.18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21476","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21476","date":"2026-10-08","epss":0.04046,"percentile":0.90365}],"risk":2.023,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21476"},"relatedVulnerabilities":[{"id":"CVE-2022-21476","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21476","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21476","date":"2026-10-08","epss":0.04046,"percentile":0.90365}],"urls":["https://lists.debian.org/debian-lts-announce/2022/05/msg00017.html","https://security.netapp.com/advisory/ntap-20220429-0006/","https://www.debian.org/security/2022/dsa-5128","https://www.debian.org/security/2022/dsa-5131","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21476","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)."}]},{"artifact":{"id":"d12e5c57a00d0dbc","cpes":["cpe:2.3:a:org.springframework:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-web:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_web:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_web:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-web","purl":"pkg:maven/org.springframework/spring-web@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-web-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-web","archiveDigests":[{"value":"d5b064196dc014519e751df549b4cc6a753fb191","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-web-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.3.33"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hgjh-9rj2-g67j","versionConstraint":"<5.3.33 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-web","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hgjh-9rj2-g67j","fix":{"state":"fixed","versions":["5.3.33"],"available":[{"date":"2024-03-19","kind":"first-observed","version":"5.3.33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22259","cwe":"CWE-601","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22259","date":"2026-10-08","epss":0.02573,"percentile":0.84713}],"risk":2.00694,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-22259","https://spring.io/security/cve-2024-22259","https://github.com/spring-projects/spring-framework/commit/297cbae2990e1413537c55845a7e0ea0ffd9f9bb","https://github.com/spring-projects/spring-framework/commit/381f790329a48b74c2a49fc1384dd68ca9153501","https://github.com/spring-projects/spring-framework/commit/f2fd2f12269c6a781c5b2c20b3c24141055a3d68","https://security.netapp.com/advisory/ntap-20240524-0002"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hgjh-9rj2-g67j","description":"Spring Framework URL Parsing with Host Validation Vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-22259","cvss":[{"type":"Secondary","source":"security@vmware.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-22259","cwe":"CWE-601","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-22259","date":"2026-10-08","epss":0.02573,"percentile":0.84713}],"urls":["https://security.netapp.com/advisory/ntap-20240524-0002/","https://spring.io/security/cve-2024-22259"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-22259","description":"Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as  CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-2388","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-2388","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-2388","date":"2026-10-08","epss":0.04008,"percentile":0.90288}],"risk":2.004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-2388"},"relatedVulnerabilities":[{"id":"CVE-2021-2388","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"impactScore":6.5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-2388","date":"2026-10-08","epss":0.04008,"percentile":0.90288}],"urls":["https://lists.debian.org/debian-lts-announce/2021/08/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20210723-0002/","https://www.debian.org/security/2021/dsa-4946","https://www.oracle.com/security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-2388","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23990","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23990","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23990","date":"2026-10-08","epss":0.03992,"percentile":0.90252}],"risk":1.9959999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23990"},"relatedVulnerabilities":[{"id":"CVE-2022-23990","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23990","date":"2026-10-08","epss":0.03992,"percentile":0.90252}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/551","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/34NXVL2RZC2YZRV74ZQ3RNFB7WCEUP7D/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7FF2UH7MPXKTADYSJUAHI2Y5UHBSHUH/","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.tenable.com/security/tns-2022-05"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23990","description":"Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.83"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fccv-jmmp-qg76","versionConstraint":">=9.0.0-M1,<9.0.83 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-fccv-jmmp-qg76","fix":{"state":"fixed","versions":["9.0.83"],"available":[{"date":"2023-12-22","kind":"first-observed","version":"9.0.83"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-46589","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2023-46589","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-46589","date":"2026-10-08","epss":0.02651,"percentile":0.8519}],"risk":1.9882499999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-46589","https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr","http://www.openwall.com/lists/oss-security/2023/11/28/2","https://github.com/apache/tomcat/commit/6f181e1062a472bc5f0234980f66cbde42c1041b","https://github.com/apache/tomcat/commit/7a2d8818fcea0b51747a67af9510ce7977245ebd","https://github.com/apache/tomcat/commit/aa92971e879a519384c517febc39fd04c48d4642","https://github.com/apache/tomcat/commit/b5776d769bffeade865061bc8ecbeb2b56167b08","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-9.html","https://www.openwall.com/lists/oss-security/2023/11/28/2","https://lists.debian.org/debian-lts-announce/2024/01/msg00001.html","https://security.netapp.com/advisory/ntap-20231214-0009"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fccv-jmmp-qg76","description":"Apache Tomcat Improper Input Validation vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2023-46589","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-46589","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2023-46589","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-46589","date":"2026-10-08","epss":0.02651,"percentile":0.8519}],"urls":["https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr","https://www.openwall.com/lists/oss-security/2023/11/28/2","https://lists.debian.org/debian-lts-announce/2024/01/msg00001.html","https://security.netapp.com/advisory/ntap-20231214-0009/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-46589","description":"Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single \nrequest as multiple requests leading to the possibility of request \nsmuggling when behind a reverse proxy.\n\n\nOlder, EOL versions may also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14583","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14583","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14583","date":"2026-10-08","epss":0.0392,"percentile":0.90064}],"risk":1.96,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14583"},"relatedVulnerabilities":[{"id":"CVE-2020-14583","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"impactScore":6.5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14583","date":"2026-10-08","epss":0.0392,"percentile":0.90064}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14583","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-3446","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-3446","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-3446","date":"2026-10-08","epss":0.06531,"percentile":0.93621}],"risk":1.9593000000000003,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-3446"},"relatedVulnerabilities":[{"id":"CVE-2023-3446","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-3446","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-3446","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-3446","date":"2026-10-08","epss":0.06531,"percentile":0.93621}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1fa20cf2f506113c761777127a38bce5068740eb","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8780a896543a654e757db1b9396383f9d8095528","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9a0a4d3c1e7138915563c0df4fe6a3f9377b839c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc9867c1e03c22ebf56943be205202e576aabf23","https://www.openssl.org/news/secadv/20230719.txt","http://www.openwall.com/lists/oss-security/2023/07/19/4","http://www.openwall.com/lists/oss-security/2023/07/19/5","http://www.openwall.com/lists/oss-security/2023/07/19/6","http://www.openwall.com/lists/oss-security/2023/07/31/1","http://www.openwall.com/lists/oss-security/2024/05/16/1","https://lists.debian.org/debian-lts-announce/2023/08/msg00019.html","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230803-0011/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-3446","description":"Issue summary: Checking excessively long DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_check(), DH_check_ex()\nor EVP_PKEY_param_check() to check a DH key or DH parameters may experience long\ndelays. Where the key or parameters that are being checked have been obtained\nfrom an untrusted source this may lead to a Denial of Service.\n\nThe function DH_check() performs various checks on DH parameters. One of those\nchecks confirms that the modulus ('p' parameter) is not too large. Trying to use\na very large modulus is slow and OpenSSL will not normally use a modulus which\nis over 10,000 bits in length.\n\nHowever the DH_check() function checks numerous aspects of the key or parameters\nthat have been supplied. Some of those checks use the supplied modulus value\neven if it has already been found to be too large.\n\nAn application that calls DH_check() and supplies a key or parameters obtained\nfrom an untrusted source could be vulernable to a Denial of Service attack.\n\nThe function DH_check() is itself called by a number of other OpenSSL functions.\nAn application calling any of those other functions may similarly be affected.\nThe other functions affected by this are DH_check_ex() and\nEVP_PKEY_param_check().\n\nAlso vulnerable are the OpenSSL dhparam and pkeyparam command line applications\nwhen using the '-check' option.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-3446","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-3446","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-3446","date":"2026-10-08","epss":0.06531,"percentile":0.93621}],"risk":1.9593000000000003,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-3446"},"relatedVulnerabilities":[{"id":"CVE-2023-3446","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-3446","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-3446","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-3446","date":"2026-10-08","epss":0.06531,"percentile":0.93621}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1fa20cf2f506113c761777127a38bce5068740eb","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8780a896543a654e757db1b9396383f9d8095528","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9a0a4d3c1e7138915563c0df4fe6a3f9377b839c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc9867c1e03c22ebf56943be205202e576aabf23","https://www.openssl.org/news/secadv/20230719.txt","http://www.openwall.com/lists/oss-security/2023/07/19/4","http://www.openwall.com/lists/oss-security/2023/07/19/5","http://www.openwall.com/lists/oss-security/2023/07/19/6","http://www.openwall.com/lists/oss-security/2023/07/31/1","http://www.openwall.com/lists/oss-security/2024/05/16/1","https://lists.debian.org/debian-lts-announce/2023/08/msg00019.html","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230803-0011/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-3446","description":"Issue summary: Checking excessively long DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_check(), DH_check_ex()\nor EVP_PKEY_param_check() to check a DH key or DH parameters may experience long\ndelays. Where the key or parameters that are being checked have been obtained\nfrom an untrusted source this may lead to a Denial of Service.\n\nThe function DH_check() performs various checks on DH parameters. One of those\nchecks confirms that the modulus ('p' parameter) is not too large. Trying to use\na very large modulus is slow and OpenSSL will not normally use a modulus which\nis over 10,000 bits in length.\n\nHowever the DH_check() function checks numerous aspects of the key or parameters\nthat have been supplied. Some of those checks use the supplied modulus value\neven if it has already been found to be too large.\n\nAn application that calls DH_check() and supplies a key or parameters obtained\nfrom an untrusted source could be vulernable to a Denial of Service attack.\n\nThe function DH_check() is itself called by a number of other OpenSSL functions.\nAn application calling any of those other functions may similarly be affected.\nThe other functions affected by this are DH_check_ex() and\nEVP_PKEY_param_check().\n\nAlso vulnerable are the OpenSSL dhparam and pkeyparam command line applications\nwhen using the '-check' option.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue."}]},{"artifact":{"id":"de33a7c2f29642ef","cpes":["cpe:2.3:a:com.squareup.retrofit2:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:retrofit2:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:retrofit:retrofit:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:squareup:retrofit:2.1.0:*:*:*:*:*:*:*"],"name":"retrofit","purl":"pkg:maven/com.squareup.retrofit2/retrofit@2.1.0","type":"java-archive","version":"2.1.0","language":"java","licenses":[],"metadata":{"pomGroupID":"com.squareup.retrofit2","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/retrofit-2.1.0.jar","manifestName":"","pomArtifactID":"retrofit","archiveDigests":[{"value":"2de7cd8b95b7021b1d597f049bcb422055119f2c","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/retrofit-2.1.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j379-9jr9-w5cq","versionConstraint":">=2.0.0,<2.5.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.squareup.retrofit2:retrofit","version":"2.1.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j379-9jr9-w5cq","fix":{"state":"fixed","versions":["2.5.0"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"2.5.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000844","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000844","date":"2026-10-08","epss":0.02152,"percentile":0.8159}],"risk":1.9475600000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-1000844","https://github.com/square/retrofit/pull/2735"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j379-9jr9-w5cq","description":"XML External Entity (XXE) vulnerability in Square Retrofit"},"relatedVulnerabilities":[{"id":"CVE-2018-1000844","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","metrics":{"baseScore":6.4,"impactScore":5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000844","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000844","date":"2026-10-08","epss":0.02152,"percentile":0.8159}],"urls":["https://github.com/square/retrofit/pull/2735"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000844","description":"Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JAXB that can result in An attacker could use this to remotely read files from the file system or to perform SSRF.. This vulnerability appears to have been fixed in After commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.106"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wc4r-xq3c-5cf3","versionConstraint":">=9.0.0.M1,<=9.0.105 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wc4r-xq3c-5cf3","fix":{"state":"fixed","versions":["9.0.106"],"available":[{"date":"2025-06-17","kind":"first-observed","version":"9.0.106"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-49125","cwe":"CWE-288","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-49125","date":"2026-10-08","epss":0.03437,"percentile":0.88639}],"risk":1.9419049999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-49125","https://lists.apache.org/thread/m66cytbfrty9k7dc4cg6tl1czhsnbywk","https://github.com/apache/tomcat/commit/7617b9c247bc77ed0444dd69adcd8aa48777886c","https://github.com/apache/tomcat/commit/9418e3ff9f1f4c006b4661311ae9376c52d162b9","https://github.com/apache/tomcat/commit/d94bd36fb7eb32e790dae0339bc249069649a637","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-9.html","http://www.openwall.com/lists/oss-security/2025/06/16/2","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wc4r-xq3c-5cf3","description":"Apache Tomcat - Security constraint bypass for pre/post-resources"},"relatedVulnerabilities":[{"id":"CVE-2025-49125","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-49125","cwe":"CWE-288","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-49125","date":"2026-10-08","epss":0.03437,"percentile":0.88639}],"urls":["https://lists.apache.org/thread/m66cytbfrty9k7dc4cg6tl1czhsnbywk","http://www.openwall.com/lists/oss-security/2025/06/16/2","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-49125","description":"Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14593","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14593","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14593","date":"2026-10-08","epss":0.03846,"percentile":0.8986}],"risk":1.923,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14593"},"relatedVulnerabilities":[{"id":"CVE-2020-14593","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14593","date":"2026-10-08","epss":0.03846,"percentile":0.8986}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14593","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N)."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-46143","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-46143","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-46143","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-46143","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-46143","date":"2026-10-08","epss":0.0379,"percentile":0.897}],"risk":1.8950000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-46143"},"relatedVulnerabilities":[{"id":"CVE-2021-46143","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46143","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-46143","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-46143","date":"2026-10-08","epss":0.0379,"percentile":0.897}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/issues/532","https://github.com/libexpat/libexpat/pull/538","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220121-0006/","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-46143","description":"In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21283","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21283","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21283","cwe":"CWE-693","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21283","date":"2026-10-08","epss":0.03782,"percentile":0.89678}],"risk":1.891,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21283"},"relatedVulnerabilities":[{"id":"CVE-2022-21283","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21283","cwe":"CWE-693","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21283","date":"2026-10-08","epss":0.03782,"percentile":0.89678}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2DIN3L6L3SVZK75CKW2GPSU4HIGZR7XG/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21283","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21341","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21341","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21341","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21341","date":"2026-10-08","epss":0.03765,"percentile":0.89632}],"risk":1.8825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21341"},"relatedVulnerabilities":[{"id":"CVE-2022-21341","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21341","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21341","date":"2026-10-08","epss":0.03765,"percentile":0.89632}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21341","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21248","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21248","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2022-21248","date":"2026-10-08","epss":0.03763,"percentile":0.89624}],"risk":1.8815,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21248"},"relatedVulnerabilities":[{"id":"CVE-2022-21248","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-21248","date":"2026-10-08","epss":0.03763,"percentile":0.89624}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2DIN3L6L3SVZK75CKW2GPSU4HIGZR7XG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4J2N4FNXW6JKJBWUZH6SNI2UHCZXQXCY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPIWQ6DL5IPOT54UBWTISG5T24FQJ7MN/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21248","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.9+11-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14779","versionConstraint":"< 11.0.9+11-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14779","fix":{"state":"fixed","versions":["11.0.9+11-0ubuntu1~18.04.1"],"available":[{"date":"2020-10-27","kind":"advisory","version":"11.0.9+11-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14779","date":"2026-10-08","epss":0.03758,"percentile":0.89608}],"risk":1.879,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14779"},"relatedVulnerabilities":[{"id":"CVE-2020-14779","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14779","date":"2026-10-08","epss":0.03758,"percentile":0.89608}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/10/msg00031.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6CJCO52DHIQJHLPF6HMTC5Z2VKFRQMY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OMJMTXFJRONFT72YAEQNRFKYZZU4W3HD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XKRGVMZT3EUUWKUA6DBT56FT3UOKPHQ2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVPLGNHNJ4UJ6IO6R2XXEKCTCI2DRPDQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YCKZAI4AWSKO5O5VDXHFFKNLOZGZ3KEE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7XEONOP6JB7SD7AMUWZTLZF2L4QD546/","https://security.gentoo.org/glsa/202101-19","https://security.netapp.com/advisory/ntap-20201023-0004/","https://www.debian.org/security/2020/dsa-4779","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14779","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1549","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1549","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.6"],"available":[{"date":"2020-05-28","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1549","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1549","date":"2026-10-08","epss":0.06182,"percentile":0.93317}],"risk":1.8546,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1549"},"relatedVulnerabilities":[{"id":"CVE-2019-1549","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1549","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1549","date":"2026-10-08","epss":0.06182,"percentile":0.93317}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1b0fe00e2704b5e20334a16d3c9099d1ba2ef1be","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/","https://seclists.org/bugtraq/2019/Oct/1","https://security.netapp.com/advisory/ntap-20190919-0002/","https://support.f5.com/csp/article/K44070243","https://support.f5.com/csp/article/K44070243?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4376-1/","https://www.debian.org/security/2019/dsa-4539","https://www.openssl.org/news/secadv/20190910.txt","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1549","description":"OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-1549","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1549","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.6"],"available":[{"date":"2020-05-28","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1549","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1549","date":"2026-10-08","epss":0.06182,"percentile":0.93317}],"risk":1.8546,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1549"},"relatedVulnerabilities":[{"id":"CVE-2019-1549","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1549","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1549","date":"2026-10-08","epss":0.06182,"percentile":0.93317}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1b0fe00e2704b5e20334a16d3c9099d1ba2ef1be","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/","https://seclists.org/bugtraq/2019/Oct/1","https://security.netapp.com/advisory/ntap-20190919-0002/","https://support.f5.com/csp/article/K44070243","https://support.f5.com/csp/article/K44070243?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4376-1/","https://www.debian.org/security/2019/dsa-4539","https://www.openssl.org/news/secadv/20190910.txt","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1549","description":"OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c)."}]},{"artifact":{"id":"c67e239bf70af34c","cpes":["cpe:2.3:a:libasn1-8-heimdal:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8-heimdal:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8_heimdal:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8_heimdal:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libasn1-8-heimdal","purl":"pkg:deb/ubuntu/libasn1-8-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libasn1-8-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libasn1-8-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasn1-8-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libasn1-8-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"489fa43422e60874","cpes":["cpe:2.3:a:libgssapi3-heimdal:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3-heimdal:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3_heimdal:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3_heimdal:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libgssapi3-heimdal","purl":"pkg:deb/ubuntu/libgssapi3-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi3-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libgssapi3-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi3-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libgssapi3-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"8af38808136cd0ba","cpes":["cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4_heimdal:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4_heimdal:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libhcrypto4-heimdal","purl":"pkg:deb/ubuntu/libhcrypto4-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libhcrypto4-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libhcrypto4-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhcrypto4-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libhcrypto4-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"4fe49c3e8d200f83","cpes":["cpe:2.3:a:libheimbase1-heimdal:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1-heimdal:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1_heimdal:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1_heimdal:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libheimbase1-heimdal","purl":"pkg:deb/ubuntu/libheimbase1-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheimbase1-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libheimbase1-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheimbase1-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libheimbase1-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"5ac1d9d8c3d94a69","cpes":["cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0_heimdal:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0_heimdal:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libheimntlm0-heimdal","purl":"pkg:deb/ubuntu/libheimntlm0-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheimntlm0-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libheimntlm0-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheimntlm0-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libheimntlm0-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"5aedfa9521e17f6a","cpes":["cpe:2.3:a:libhx509-5-heimdal:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5-heimdal:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5_heimdal:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5_heimdal:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libhx509-5-heimdal","purl":"pkg:deb/ubuntu/libhx509-5-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libhx509-5-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libhx509-5-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhx509-5-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libhx509-5-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"ec3f5f14c892446a","cpes":["cpe:2.3:a:libkrb5-26-heimdal:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26-heimdal:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26_heimdal:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26_heimdal:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libkrb5-26-heimdal","purl":"pkg:deb/ubuntu/libkrb5-26-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-26-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5-26-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-26-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5-26-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"d29c0be392861a2d","cpes":["cpe:2.3:a:libroken18-heimdal:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18-heimdal:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18_heimdal:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18_heimdal:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libroken18-heimdal","purl":"pkg:deb/ubuntu/libroken18-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libroken18-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libroken18-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libroken18-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libroken18-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"4c95d1ed3ad0ede5","cpes":["cpe:2.3:a:libwind0-heimdal:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0-heimdal:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0_heimdal:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0_heimdal:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libwind0-heimdal","purl":"pkg:deb/ubuntu/libwind0-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwind0-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libwind0-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwind0-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libwind0-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3437","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-3437","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.3"],"available":[{"date":"2023-01-12","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"risk":1.8450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3437"},"relatedVulnerabilities":[{"id":"CVE-2022-3437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3437","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-3437","date":"2026-10-08","epss":0.0369,"percentile":0.89408}],"urls":["http://www.openwall.com/lists/oss-security/2023/02/08/1","https://access.redhat.com/security/cve/CVE-2022-3437","https://bugzilla.redhat.com/show_bug.cgi?id=2137774","https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html","https://security.gentoo.org/glsa/202309-06","https://security.gentoo.org/glsa/202310-06","https://security.netapp.com/advisory/ntap-20230216-0008/","https://www.samba.org/samba/security/CVE-2022-3437.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437","description":"A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack."}]},{"artifact":{"id":"91ad4ea54a8353ff","cpes":["cpe:2.3:a:perl-base:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.26.1-6ubuntu0.3?arch=amd64&distro=ubuntu-18.04&upstream=perl","type":"deb","version":"5.26.1-6ubuntu0.3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.26.1-6ubuntu0.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-12723","versionConstraint":"< 5.26.1-6ubuntu0.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"perl","version":"5.26.1-6ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-12723","fix":{"state":"fixed","versions":["5.26.1-6ubuntu0.5"],"available":[{"date":"2020-10-26","kind":"advisory","version":"5.26.1-6ubuntu0.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-12723","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12723","date":"2026-10-08","epss":0.05971,"percentile":0.93112}],"risk":1.7913,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-12723"},"relatedVulnerabilities":[{"id":"CVE-2020-12723","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-12723","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-12723","date":"2026-10-08","epss":0.05971,"percentile":0.93112}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html","https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod","https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3","https://github.com/Perl/perl5/issues/16947","https://github.com/Perl/perl5/issues/17743","https://github.com/perl/perl5/commit/66bbb51b93253a3f87d11c2695cfb7bdb782184a","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/","https://security.gentoo.org/glsa/202006-03","https://security.netapp.com/advisory/ntap-20200611-0001/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-12723","description":"regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-38546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-38546","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2023-38546","date":"2026-10-08","epss":0.05956,"percentile":0.931}],"risk":1.7868,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-38546"},"relatedVulnerabilities":[{"id":"CVE-2023-38546","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-38546","date":"2026-10-08","epss":0.05956,"percentile":0.931}],"urls":["http://seclists.org/fulldisclosure/2024/Jan/34","http://seclists.org/fulldisclosure/2024/Jan/37","http://seclists.org/fulldisclosure/2024/Jan/38","https://curl.se/docs/CVE-2023-38546.html","https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214057","https://support.apple.com/kb/HT214058","https://support.apple.com/kb/HT214063","https://lists.debian.org/debian-lts-announce/2023/10/msg00016.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-093430.html","https://cert-portal.siemens.com/productcert/html/ssa-832273.html","https://cert-portal.siemens.com/productcert/html/ssa-943925.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-38546","description":"This flaw allows an attacker to insert cookies at will into a running program\nusing libcurl, if the specific series of conditions are met.\n\nlibcurl performs transfers. In its API, an application creates \"easy handles\"\nthat are the individual handles for single transfers.\n\nlibcurl provides a function call that duplicates en easy handle called\n[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).\n\nIf a transfer has cookies enabled when the handle is duplicated, the\ncookie-enable state is also cloned - but without cloning the actual\ncookies. If the source handle did not read any cookies from a specific file on\ndisk, the cloned version of the handle would instead store the file name as\n`none` (using the four ASCII letters, no quotes).\n\nSubsequent use of the cloned handle that does not explicitly set a source to\nload cookies from would then inadvertently load cookies from a file named\n`none` - if such a file exists and is readable in the current directory of the\nprogram using libcurl. And if using the correct file format of course."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-38546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-38546","fix":{"state":"wont-fix","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2023-38546","date":"2026-10-08","epss":0.05956,"percentile":0.931}],"risk":1.7868,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-38546"},"relatedVulnerabilities":[{"id":"CVE-2023-38546","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-38546","date":"2026-10-08","epss":0.05956,"percentile":0.931}],"urls":["http://seclists.org/fulldisclosure/2024/Jan/34","http://seclists.org/fulldisclosure/2024/Jan/37","http://seclists.org/fulldisclosure/2024/Jan/38","https://curl.se/docs/CVE-2023-38546.html","https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214057","https://support.apple.com/kb/HT214058","https://support.apple.com/kb/HT214063","https://lists.debian.org/debian-lts-announce/2023/10/msg00016.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-093430.html","https://cert-portal.siemens.com/productcert/html/ssa-832273.html","https://cert-portal.siemens.com/productcert/html/ssa-943925.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-38546","description":"This flaw allows an attacker to insert cookies at will into a running program\nusing libcurl, if the specific series of conditions are met.\n\nlibcurl performs transfers. In its API, an application creates \"easy handles\"\nthat are the individual handles for single transfers.\n\nlibcurl provides a function call that duplicates en easy handle called\n[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).\n\nIf a transfer has cookies enabled when the handle is duplicated, the\ncookie-enable state is also cloned - but without cloning the actual\ncookies. If the source handle did not read any cookies from a specific file on\ndisk, the cloned version of the handle would instead store the file name as\n`none` (using the four ASCII letters, no quotes).\n\nSubsequent use of the cloned handle that does not explicitly set a source to\nload cookies from would then inadvertently load cookies from a file named\n`none` - if such a file exists and is readable in the current directory of the\nprogram using libcurl. And if using the correct file format of course."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.11+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-2163","versionConstraint":"< 11.0.11+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-2163","fix":{"state":"fixed","versions":["11.0.11+9-0ubuntu2~18.04"],"available":[{"date":"2021-04-27","kind":"advisory","version":"11.0.11+9-0ubuntu2~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-2163","date":"2026-10-08","epss":0.03566,"percentile":0.89036}],"risk":1.783,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-2163"},"relatedVulnerabilities":[{"id":"CVE-2021-2163","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-2163","date":"2026-10-08","epss":0.03566,"percentile":0.89036}],"urls":["https://lists.debian.org/debian-lts-announce/2021/04/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5ACX4JEVYH6H4PSMGMYWTGABPOFPH3TS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFXOKM2233JVGYDOWW77BN54X3GZTIBK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CG7EWXSO6JUCVHP7R3SOZQ7WPNBOISJH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MAULPCQFLAMBJIS27YLNNX6IHRFJMVP4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MVDY4T5XMSYDQT6RRKPMRCV4MVGS7KXF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UD3JEP4HPLK7MNZHVUMKIJPBP74M3A2V/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20210513-0001/","https://www.debian.org/security/2021/dsa-4899","https://www.oracle.com/security-alerts/cpuapr2021.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-2163","description":"Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N)."}]},{"artifact":{"id":"991c4985867726c0","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/ubuntu/libp11-kit0@0.23.9-2?arch=amd64&distro=ubuntu-18.04&upstream=p11-kit","type":"deb","version":"0.23.9-2","language":"","licenses":["sha256:077e865058e6f7212e89794c84ca99c3e97b9b10e4d1f8253f93d96825e4f6b0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"fix":{"suggestedVersion":"0.23.9-2ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-29363","versionConstraint":"< 0.23.9-2ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"p11-kit","version":"0.23.9-2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-29363","fix":{"state":"fixed","versions":["0.23.9-2ubuntu0.1"],"available":[{"date":"2021-01-05","kind":"advisory","version":"0.23.9-2ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-29363","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-29363","date":"2026-10-08","epss":0.03528,"percentile":0.88926}],"risk":1.764,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-29363"},"relatedVulnerabilities":[{"id":"CVE-2020-29363","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-29363","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-29363","date":"2026-10-08","epss":0.03528,"percentile":0.88926}],"urls":["https://github.com/p11-glue/p11-kit/releases","https://github.com/p11-glue/p11-kit/security/advisories/GHSA-5j67-fw89-fp6x","https://www.debian.org/security/2021/dsa-4822","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-29363","description":"An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-9143","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-9143","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-9143","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-9143","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-9143","date":"2026-10-08","epss":0.05842,"percentile":0.92986}],"risk":1.7526,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-9143"},"relatedVulnerabilities":[{"id":"CVE-2024-9143","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9143","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-9143","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-9143","date":"2026-10-08","epss":0.05842,"percentile":0.92986}],"urls":["https://github.com/openssl/openssl/commit/72ae83ad214d2eef262461365a1975707f862712","https://github.com/openssl/openssl/commit/bc7e04d7c8d509fb78fc0e285aa948fb0da04700","https://github.com/openssl/openssl/commit/c0d3e4d32d2805f49bec30547f225bc4d092e1f4","https://github.com/openssl/openssl/commit/fdf6723362ca51bd883295efe206cb5b1cfa5154","https://github.openssl.org/openssl/extended-releases/commit/8efc0cbaa8ebba8e116f7b81a876a4123594d86a","https://github.openssl.org/openssl/extended-releases/commit/9d576994cec2b7aa37a91740ea7e680810957e41","https://openssl-library.org/news/secadv/20241016.txt","http://www.openwall.com/lists/oss-security/2024/10/16/1","http://www.openwall.com/lists/oss-security/2024/10/23/1","http://www.openwall.com/lists/oss-security/2024/10/24/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20241101-0001/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-9143","description":"Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted\nexplicit values for the field polynomial can lead to out-of-bounds memory reads\nor writes.\n\nImpact summary: Out of bound memory writes can lead to an application crash or\neven a possibility of a remote code execution, however, in all the protocols\ninvolving Elliptic Curve Cryptography that we're aware of, either only \"named\ncurves\" are supported, or, if explicit curve parameters are supported, they\nspecify an X9.62 encoding of binary (GF(2^m)) curves that can't represent\nproblematic input values. Thus the likelihood of existence of a vulnerable\napplication is low.\n\nIn particular, the X9.62 encoding is used for ECC keys in X.509 certificates,\nso problematic inputs cannot occur in the context of processing X.509\ncertificates.  Any problematic use-cases would have to be using an \"exotic\"\ncurve encoding.\n\nThe affected APIs include: EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(),\nand various supporting BN_GF2m_*() functions.\n\nApplications working with \"exotic\" explicit binary (GF(2^m)) curve parameters,\nthat make it possible to represent invalid field polynomials with a zero\nconstant term, via the above or similar APIs, may terminate abruptly as a\nresult of reading or writing outside of array bounds.  Remote code execution\ncannot easily be ruled out.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-9143","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-9143","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-9143","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-9143","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-9143","date":"2026-10-08","epss":0.05842,"percentile":0.92986}],"risk":1.7526,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-9143"},"relatedVulnerabilities":[{"id":"CVE-2024-9143","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9143","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-9143","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-9143","date":"2026-10-08","epss":0.05842,"percentile":0.92986}],"urls":["https://github.com/openssl/openssl/commit/72ae83ad214d2eef262461365a1975707f862712","https://github.com/openssl/openssl/commit/bc7e04d7c8d509fb78fc0e285aa948fb0da04700","https://github.com/openssl/openssl/commit/c0d3e4d32d2805f49bec30547f225bc4d092e1f4","https://github.com/openssl/openssl/commit/fdf6723362ca51bd883295efe206cb5b1cfa5154","https://github.openssl.org/openssl/extended-releases/commit/8efc0cbaa8ebba8e116f7b81a876a4123594d86a","https://github.openssl.org/openssl/extended-releases/commit/9d576994cec2b7aa37a91740ea7e680810957e41","https://openssl-library.org/news/secadv/20241016.txt","http://www.openwall.com/lists/oss-security/2024/10/16/1","http://www.openwall.com/lists/oss-security/2024/10/23/1","http://www.openwall.com/lists/oss-security/2024/10/24/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20241101-0001/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-9143","description":"Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted\nexplicit values for the field polynomial can lead to out-of-bounds memory reads\nor writes.\n\nImpact summary: Out of bound memory writes can lead to an application crash or\neven a possibility of a remote code execution, however, in all the protocols\ninvolving Elliptic Curve Cryptography that we're aware of, either only \"named\ncurves\" are supported, or, if explicit curve parameters are supported, they\nspecify an X9.62 encoding of binary (GF(2^m)) curves that can't represent\nproblematic input values. Thus the likelihood of existence of a vulnerable\napplication is low.\n\nIn particular, the X9.62 encoding is used for ECC keys in X.509 certificates,\nso problematic inputs cannot occur in the context of processing X.509\ncertificates.  Any problematic use-cases would have to be using an \"exotic\"\ncurve encoding.\n\nThe affected APIs include: EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(),\nand various supporting BN_GF2m_*() functions.\n\nApplications working with \"exotic\" explicit binary (GF(2^m)) curve parameters,\nthat make it possible to represent invalid field polynomials with a zero\nconstant term, via the above or similar APIs, may terminate abruptly as a\nresult of reading or writing outside of array bounds.  Remote code execution\ncannot easily be ruled out.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21360","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21360","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21360","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21360","date":"2026-10-08","epss":0.03486,"percentile":0.88802}],"risk":1.743,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21360"},"relatedVulnerabilities":[{"id":"CVE-2022-21360","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21360","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21360","date":"2026-10-08","epss":0.03486,"percentile":0.88802}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21360","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21365","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21365","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2022-21365","date":"2026-10-08","epss":0.03486,"percentile":0.88802}],"risk":1.743,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21365"},"relatedVulnerabilities":[{"id":"CVE-2022-21365","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-21365","date":"2026-10-08","epss":0.03486,"percentile":0.88802}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21365","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21299","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21299","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21299","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21299","date":"2026-10-08","epss":0.03458,"percentile":0.88709}],"risk":1.729,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21299"},"relatedVulnerabilities":[{"id":"CVE-2022-21299","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21299","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21299","date":"2026-10-08","epss":0.03458,"percentile":0.88709}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21299","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-2369","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-2369","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-2369","date":"2026-10-08","epss":0.03444,"percentile":0.88668}],"risk":1.722,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-2369"},"relatedVulnerabilities":[{"id":"CVE-2021-2369","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-2369","date":"2026-10-08","epss":0.03444,"percentile":0.88668}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1982879","https://lists.debian.org/debian-lts-announce/2021/08/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20210723-0002/","https://www.debian.org/security/2021/dsa-4946","https://www.oracle.com/security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-2369","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Library). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-22823","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-22823","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-22823","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22823","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22823","date":"2026-10-08","epss":0.03404,"percentile":0.88532}],"risk":1.702,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-22823"},"relatedVulnerabilities":[{"id":"CVE-2022-22823","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22823","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22823","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22823","date":"2026-10-08","epss":0.03404,"percentile":0.88532}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/539","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22823","description":"build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-22824","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-22824","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-22824","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22824","date":"2026-10-08","epss":0.03404,"percentile":0.88532}],"risk":1.702,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-22824"},"relatedVulnerabilities":[{"id":"CVE-2022-22824","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22824","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22824","date":"2026-10-08","epss":0.03404,"percentile":0.88532}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/539","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22824","description":"defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14577","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14577","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14577","date":"2026-10-08","epss":0.0338,"percentile":0.88451}],"risk":1.69,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14577"},"relatedVulnerabilities":[{"id":"CVE-2020-14577","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14577","date":"2026-10-08","epss":0.0338,"percentile":0.88451}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14577","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14573","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14573","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14573","date":"2026-10-08","epss":0.03377,"percentile":0.88441}],"risk":1.6885000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14573"},"relatedVulnerabilities":[{"id":"CVE-2020-14573","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14573","date":"2026-10-08","epss":0.03377,"percentile":0.88441}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14573","description":"Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"991c4985867726c0","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.23.9-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.23.9-2:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/ubuntu/libp11-kit0@0.23.9-2?arch=amd64&distro=ubuntu-18.04&upstream=p11-kit","type":"deb","version":"0.23.9-2","language":"","licenses":["sha256:077e865058e6f7212e89794c84ca99c3e97b9b10e4d1f8253f93d96825e4f6b0"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"fix":{"suggestedVersion":"0.23.9-2ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-29361","versionConstraint":"< 0.23.9-2ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"p11-kit","version":"0.23.9-2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-29361","fix":{"state":"fixed","versions":["0.23.9-2ubuntu0.1"],"available":[{"date":"2021-01-05","kind":"advisory","version":"0.23.9-2ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-29361","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-29361","date":"2026-10-08","epss":0.03363,"percentile":0.88395}],"risk":1.6815,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-29361"},"relatedVulnerabilities":[{"id":"CVE-2020-29361","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-29361","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-29361","date":"2026-10-08","epss":0.03363,"percentile":0.88395}],"urls":["https://github.com/p11-glue/p11-kit/releases","https://github.com/p11-glue/p11-kit/security/advisories/GHSA-q4r3-hm6m-mvc2","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/01/msg00002.html","https://www.debian.org/security/2021/dsa-4822"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-29361","description":"An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21294","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21294","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21294","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21294","date":"2026-10-08","epss":0.0335,"percentile":0.88351}],"risk":1.675,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21294"},"relatedVulnerabilities":[{"id":"CVE-2022-21294","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21294","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21294","date":"2026-10-08","epss":0.0335,"percentile":0.88351}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21294","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-5535","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-5535","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-5535","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-5535","date":"2026-10-08","epss":0.05582,"percentile":0.92684}],"risk":1.6746,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-5535"},"relatedVulnerabilities":[{"id":"CVE-2024-5535","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-5535","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-5535","date":"2026-10-08","epss":0.05582,"percentile":0.92684}],"urls":["https://github.com/openssl/openssl/commit/4ada436a1946cbb24db5ab4ca082b69c1bc10f37","https://github.com/openssl/openssl/commit/99fb785a5f85315b95288921a321a935ea29a51e","https://github.com/openssl/openssl/commit/cf6f91f6121f4db167405db2f0de410a456f260c","https://github.com/openssl/openssl/commit/e86ac436f0bd54d4517745483e2315650fae7b2c","https://github.openssl.org/openssl/extended-releases/commit/9947251413065a05189a63c9b7a6c1d4e224c21c","https://github.openssl.org/openssl/extended-releases/commit/b78ec0824da857223486660177d3b1f255c65d87","https://www.openssl.org/news/secadv/20240627.txt","http://www.openwall.com/lists/oss-security/2024/06/27/1","http://www.openwall.com/lists/oss-security/2024/06/28/4","http://www.openwall.com/lists/oss-security/2024/08/15/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240712-0005/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-5535","description":"Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an\nempty supported client protocols buffer may cause a crash or memory contents to\nbe sent to the peer.\n\nImpact summary: A buffer overread can have a range of potential consequences\nsuch as unexpected application beahviour or a crash. In particular this issue\ncould result in up to 255 bytes of arbitrary private data from memory being sent\nto the peer leading to a loss of confidentiality. However, only applications\nthat directly call the SSL_select_next_proto function with a 0 length list of\nsupported client protocols are affected by this issue. This would normally never\nbe a valid scenario and is typically not under attacker control but may occur by\naccident in the case of a configuration or programming error in the calling\napplication.\n\nThe OpenSSL API function SSL_select_next_proto is typically used by TLS\napplications that support ALPN (Application Layer Protocol Negotiation) or NPN\n(Next Protocol Negotiation). NPN is older, was never standardised and\nis deprecated in favour of ALPN. We believe that ALPN is significantly more\nwidely deployed than NPN. The SSL_select_next_proto function accepts a list of\nprotocols from the server and a list of protocols from the client and returns\nthe first protocol that appears in the server list that also appears in the\nclient list. In the case of no overlap between the two lists it returns the\nfirst item in the client list. In either case it will signal whether an overlap\nbetween the two lists was found. In the case where SSL_select_next_proto is\ncalled with a zero length client list it fails to notice this condition and\nreturns the memory immediately following the client list pointer (and reports\nthat there was no overlap in the lists).\n\nThis function is typically called from a server side application callback for\nALPN or a client side application callback for NPN. In the case of ALPN the list\nof protocols supplied by the client is guaranteed by libssl to never be zero in\nlength. The list of server protocols comes from the application and should never\nnormally be expected to be of zero length. In this case if the\nSSL_select_next_proto function has been called as expected (with the list\nsupplied by the client passed in the client/client_len parameters), then the\napplication will not be vulnerable to this issue. If the application has\naccidentally been configured with a zero length server list, and has\naccidentally passed that zero length server list in the client/client_len\nparameters, and has additionally failed to correctly handle a \"no overlap\"\nresponse (which would normally result in a handshake failure in ALPN) then it\nwill be vulnerable to this problem.\n\nIn the case of NPN, the protocol permits the client to opportunistically select\na protocol when there is no overlap. OpenSSL returns the first client protocol\nin the no overlap case in support of this. The list of client protocols comes\nfrom the application and should never normally be expected to be of zero length.\nHowever if the SSL_select_next_proto function is accidentally called with a\nclient_len of 0 then an invalid memory pointer will be returned instead. If the\napplication uses this output as the opportunistic protocol then the loss of\nconfidentiality will occur.\n\nThis issue has been assessed as Low severity because applications are most\nlikely to be vulnerable if they are using NPN instead of ALPN - but NPN is not\nwidely used. It also requires an application configuration or programming error.\nFinally, this issue would not typically be under attacker control making active\nexploitation unlikely.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.\n\nDue to the low severity of this issue we are not issuing new releases of\nOpenSSL at this time. The fix will be included in the next releases when they\nbecome available."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-5535","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-5535","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-5535","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-5535","date":"2026-10-08","epss":0.05582,"percentile":0.92684}],"risk":1.6746,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-5535"},"relatedVulnerabilities":[{"id":"CVE-2024-5535","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-5535","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-5535","date":"2026-10-08","epss":0.05582,"percentile":0.92684}],"urls":["https://github.com/openssl/openssl/commit/4ada436a1946cbb24db5ab4ca082b69c1bc10f37","https://github.com/openssl/openssl/commit/99fb785a5f85315b95288921a321a935ea29a51e","https://github.com/openssl/openssl/commit/cf6f91f6121f4db167405db2f0de410a456f260c","https://github.com/openssl/openssl/commit/e86ac436f0bd54d4517745483e2315650fae7b2c","https://github.openssl.org/openssl/extended-releases/commit/9947251413065a05189a63c9b7a6c1d4e224c21c","https://github.openssl.org/openssl/extended-releases/commit/b78ec0824da857223486660177d3b1f255c65d87","https://www.openssl.org/news/secadv/20240627.txt","http://www.openwall.com/lists/oss-security/2024/06/27/1","http://www.openwall.com/lists/oss-security/2024/06/28/4","http://www.openwall.com/lists/oss-security/2024/08/15/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240712-0005/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-5535","description":"Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an\nempty supported client protocols buffer may cause a crash or memory contents to\nbe sent to the peer.\n\nImpact summary: A buffer overread can have a range of potential consequences\nsuch as unexpected application beahviour or a crash. In particular this issue\ncould result in up to 255 bytes of arbitrary private data from memory being sent\nto the peer leading to a loss of confidentiality. However, only applications\nthat directly call the SSL_select_next_proto function with a 0 length list of\nsupported client protocols are affected by this issue. This would normally never\nbe a valid scenario and is typically not under attacker control but may occur by\naccident in the case of a configuration or programming error in the calling\napplication.\n\nThe OpenSSL API function SSL_select_next_proto is typically used by TLS\napplications that support ALPN (Application Layer Protocol Negotiation) or NPN\n(Next Protocol Negotiation). NPN is older, was never standardised and\nis deprecated in favour of ALPN. We believe that ALPN is significantly more\nwidely deployed than NPN. The SSL_select_next_proto function accepts a list of\nprotocols from the server and a list of protocols from the client and returns\nthe first protocol that appears in the server list that also appears in the\nclient list. In the case of no overlap between the two lists it returns the\nfirst item in the client list. In either case it will signal whether an overlap\nbetween the two lists was found. In the case where SSL_select_next_proto is\ncalled with a zero length client list it fails to notice this condition and\nreturns the memory immediately following the client list pointer (and reports\nthat there was no overlap in the lists).\n\nThis function is typically called from a server side application callback for\nALPN or a client side application callback for NPN. In the case of ALPN the list\nof protocols supplied by the client is guaranteed by libssl to never be zero in\nlength. The list of server protocols comes from the application and should never\nnormally be expected to be of zero length. In this case if the\nSSL_select_next_proto function has been called as expected (with the list\nsupplied by the client passed in the client/client_len parameters), then the\napplication will not be vulnerable to this issue. If the application has\naccidentally been configured with a zero length server list, and has\naccidentally passed that zero length server list in the client/client_len\nparameters, and has additionally failed to correctly handle a \"no overlap\"\nresponse (which would normally result in a handshake failure in ALPN) then it\nwill be vulnerable to this problem.\n\nIn the case of NPN, the protocol permits the client to opportunistically select\na protocol when there is no overlap. OpenSSL returns the first client protocol\nin the no overlap case in support of this. The list of client protocols comes\nfrom the application and should never normally be expected to be of zero length.\nHowever if the SSL_select_next_proto function is accidentally called with a\nclient_len of 0 then an invalid memory pointer will be returned instead. If the\napplication uses this output as the opportunistic protocol then the loss of\nconfidentiality will occur.\n\nThis issue has been assessed as Low severity because applications are most\nlikely to be vulnerable if they are using NPN instead of ALPN - but NPN is not\nwidely used. It also requires an application configuration or programming error.\nFinally, this issue would not typically be under attacker control making active\nexploitation unlikely.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.\n\nDue to the low severity of this issue we are not issuing new releases of\nOpenSSL at this time. The fix will be included in the next releases when they\nbecome available."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-25313","versionConstraint":"< 2.2.5-3ubuntu0.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-25313","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.7"],"available":[{"date":"2022-03-10","kind":"advisory","version":"2.2.5-3ubuntu0.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-25313","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25313","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25313","date":"2026-10-08","epss":0.03295,"percentile":0.88164}],"risk":1.6475,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-25313"},"relatedVulnerabilities":[{"id":"CVE-2022-25313","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25313","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-25313","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-25313","date":"2026-10-08","epss":0.03295,"percentile":0.88164}],"urls":["http://www.openwall.com/lists/oss-security/2022/02/19/1","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/558","https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220303-0008/","https://www.debian.org/security/2022/dsa-5085","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25313","description":"In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14581","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14581","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14581","date":"2026-10-08","epss":0.03284,"percentile":0.88115}],"risk":1.6420000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14581"},"relatedVulnerabilities":[{"id":"CVE-2020-14581","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14581","date":"2026-10-08","epss":0.03284,"percentile":0.88115}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://kc.mcafee.com/corporate/index?page=content&id=SB10332","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14581","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"9f11bcfb19ae96af","cpes":["cpe:2.3:a:dpkg:dpkg:1.19.0.5ubuntu2.3:*:*:*:*:*:*:*"],"name":"dpkg","purl":"pkg:deb/ubuntu/dpkg@1.19.0.5ubuntu2.3?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.19.0.5ubuntu2.3","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2+","public-domain-md5","public-domain-s-s-d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dpkg/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/dpkg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/dpkg.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/dpkg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/dpkg.list"},{"path":"/var/lib/dpkg/info/dpkg.postinst","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/dpkg.postinst"},{"path":"/var/lib/dpkg/info/dpkg.postrm","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/dpkg.postrm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.0.5ubuntu2.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-1664","versionConstraint":"< 1.19.0.5ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"dpkg","version":"1.19.0.5ubuntu2.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-1664","fix":{"state":"fixed","versions":["1.19.0.5ubuntu2.4"],"available":[{"date":"2022-05-26","kind":"advisory","version":"1.19.0.5ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-1664","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1664","date":"2026-10-08","epss":0.0324,"percentile":0.87919}],"risk":1.6199999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-1664"},"relatedVulnerabilities":[{"id":"CVE-2022-1664","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1664","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1664","date":"2026-10-08","epss":0.0324,"percentile":0.87919}],"urls":["https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=1f23dddc17f69c9598477098c7fb9936e15fa495","https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=58814cacee39c4ce9e2cd0e3a3b9b57ad437eff5","https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=7a6c03cb34d4a09f35df2f10779cbf1b70a5200b","https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=faa4c92debe45412bfcf8a44f26e827800bb24be","https://lists.debian.org/debian-lts-announce/2022/05/msg00033.html","https://lists.debian.org/debian-security-announce/2022/msg00115.html","https://security.netapp.com/advisory/ntap-20221007-0002/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1664","description":"Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs."}]},{"artifact":{"id":"86469caa4d25f98f","cpes":["cpe:2.3:a:liblz4-1:liblz4-1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:liblz4-1:liblz4_1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:liblz4_1:liblz4-1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:liblz4_1:liblz4_1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:liblz4:liblz4-1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:liblz4:liblz4_1:0.0\\~r131-2ubuntu3:*:*:*:*:*:*:*"],"name":"liblz4-1","purl":"pkg:deb/ubuntu/liblz4-1@0.0~r131-2ubuntu3?arch=amd64&distro=ubuntu-18.04&upstream=lz4","type":"deb","version":"0.0~r131-2ubuntu3","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblz4-1/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/liblz4-1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblz4-1:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/liblz4-1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"lz4"}]},"matchDetails":[{"fix":{"suggestedVersion":"0.0~r131-2ubuntu3.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3520","versionConstraint":"< 0.0~r131-2ubuntu3.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"lz4","version":"0.0~r131-2ubuntu3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3520","fix":{"state":"fixed","versions":["0.0~r131-2ubuntu3.1"],"available":[{"date":"2021-05-26","kind":"advisory","version":"0.0~r131-2ubuntu3.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3520","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3520","cwe":"CWE-190","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3520","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3520","date":"2026-10-08","epss":0.03216,"percentile":0.87832}],"risk":1.608,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3520"},"relatedVulnerabilities":[{"id":"CVE-2021-3520","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3520","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3520","cwe":"CWE-190","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2021-3520","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3520","date":"2026-10-08","epss":0.03216,"percentile":0.87832}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1954559","https://security.netapp.com/advisory/ntap-20211104-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3520","description":"There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21366","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21366","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21366","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21366","date":"2026-10-08","epss":0.03216,"percentile":0.87832}],"risk":1.608,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21366"},"relatedVulnerabilities":[{"id":"CVE-2022-21366","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21366","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21366","date":"2026-10-08","epss":0.03216,"percentile":0.87832}],"urls":["https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21366","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"685ff832fa5df143","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-6096","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-6096","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"risk":1.6062,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-6096"},"relatedVulnerabilities":[{"id":"CVE-2020-6096","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"urls":["https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYXTDOOB4PQGTYAMZAZNJIB3FF6YQXI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/URXOIA2LDUKHQXK4BE55BQBRI6ZZG3Y6/","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=25620","https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1019"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-6096","description":"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data."}]},{"artifact":{"id":"71315b6fa75a7166","cpes":["cpe:2.3:a:libc6:libc6:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-6096","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-6096","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"risk":1.6062,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-6096"},"relatedVulnerabilities":[{"id":"CVE-2020-6096","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"urls":["https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYXTDOOB4PQGTYAMZAZNJIB3FF6YQXI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/URXOIA2LDUKHQXK4BE55BQBRI6ZZG3Y6/","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=25620","https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1019"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-6096","description":"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data."}]},{"artifact":{"id":"62a0389fd254614a","cpes":["cpe:2.3:a:locales:locales:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.27-3ubuntu1?arch=all&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-6096","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-6096","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"risk":1.6062,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-6096"},"relatedVulnerabilities":[{"id":"CVE-2020-6096","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"urls":["https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYXTDOOB4PQGTYAMZAZNJIB3FF6YQXI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/URXOIA2LDUKHQXK4BE55BQBRI6ZZG3Y6/","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=25620","https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1019"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-6096","description":"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data."}]},{"artifact":{"id":"6c475aa8af85f1cd","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-6096","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-6096","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"risk":1.6062,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-6096"},"relatedVulnerabilities":[{"id":"CVE-2020-6096","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"talos-cna@cisco.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-6096","cwe":"CWE-195","type":"Secondary","source":"talos-cna@cisco.com"},{"cve":"CVE-2020-6096","cwe":"CWE-191","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2020-6096","cwe":"CWE-681","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-6096","date":"2026-10-08","epss":0.05354,"percentile":0.92432}],"urls":["https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPYXTDOOB4PQGTYAMZAZNJIB3FF6YQXI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/URXOIA2LDUKHQXK4BE55BQBRI6ZZG3Y6/","https://security.gentoo.org/glsa/202101-20","https://sourceware.org/bugzilla/show_bug.cgi?id=25620","https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1019"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-6096","description":"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data."}]},{"artifact":{"id":"d228f0f9dd924b4f","cpes":["cpe:2.3:a:libjpeg-turbo8:libjpeg-turbo8:1.5.2-0ubuntu5.18.04.3:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg-turbo8:libjpeg_turbo8:1.5.2-0ubuntu5.18.04.3:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg_turbo8:libjpeg-turbo8:1.5.2-0ubuntu5.18.04.3:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg_turbo8:libjpeg_turbo8:1.5.2-0ubuntu5.18.04.3:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg:libjpeg-turbo8:1.5.2-0ubuntu5.18.04.3:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg:libjpeg_turbo8:1.5.2-0ubuntu5.18.04.3:*:*:*:*:*:*:*"],"name":"libjpeg-turbo8","purl":"pkg:deb/ubuntu/libjpeg-turbo8@1.5.2-0ubuntu5.18.04.3?arch=amd64&distro=ubuntu-18.04&upstream=libjpeg-turbo","type":"deb","version":"1.5.2-0ubuntu5.18.04.3","language":"","licenses":["sha256:193468d9eb043a180f6f9e3386f7205104908dcb8525ad39c8236990dfd452ef"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjpeg-turbo8/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libjpeg-turbo8/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjpeg-turbo8:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libjpeg-turbo8:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libjpeg-turbo"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.5.2-0ubuntu5.18.04.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-13790","versionConstraint":"< 1.5.2-0ubuntu5.18.04.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libjpeg-turbo","version":"1.5.2-0ubuntu5.18.04.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-13790","fix":{"state":"fixed","versions":["1.5.2-0ubuntu5.18.04.4"],"available":[{"date":"2020-06-09","kind":"advisory","version":"1.5.2-0ubuntu5.18.04.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-13790","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13790","date":"2026-10-08","epss":0.03205,"percentile":0.87777}],"risk":1.6025,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-13790"},"relatedVulnerabilities":[{"id":"CVE-2020-13790","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-13790","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-13790","date":"2026-10-08","epss":0.03205,"percentile":0.87777}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00031.html","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00062.html","https://github.com/libjpeg-turbo/libjpeg-turbo/commit/3de15e0c344d11d4b90f4a47136467053eb2d09a","https://github.com/libjpeg-turbo/libjpeg-turbo/issues/433","https://lists.debian.org/debian-lts-announce/2020/07/msg00033.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P4D6KNUY7YANSPH7SVQ44PJKSABFKAUB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6563YHSVZK24MPJXGJVK3CQG7JVWZGK/","https://security.gentoo.org/glsa/202010-03","https://usn.ubuntu.com/4386-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-13790","description":"libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.15+10-0ubuntu0.18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21426","versionConstraint":"< 11.0.15+10-0ubuntu0.18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21426","fix":{"state":"fixed","versions":["11.0.15+10-0ubuntu0.18.04.1"],"available":[{"date":"2022-04-26","kind":"advisory","version":"11.0.15+10-0ubuntu0.18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2022-21426","date":"2026-10-08","epss":0.03203,"percentile":0.87769}],"risk":1.6015000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21426"},"relatedVulnerabilities":[{"id":"CVE-2022-21426","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-21426","date":"2026-10-08","epss":0.03203,"percentile":0.87769}],"urls":["https://lists.debian.org/debian-lts-announce/2022/05/msg00017.html","https://security.netapp.com/advisory/ntap-20220429-0006/","https://www.debian.org/security/2022/dsa-5128","https://www.debian.org/security/2022/dsa-5131","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21426","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-4189","versionConstraint":"< 3.6.9-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-4189","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"risk":1.598,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-4189"},"relatedVulnerabilities":[{"id":"CVE-2021-4189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"urls":["https://access.redhat.com/security/cve/CVE-2021-4189","https://bugs.python.org/issue43285","https://bugzilla.redhat.com/show_bug.cgi?id=2036020","https://github.com/python/cpython/commit/0ab152c6b5d95caa2dc1a30fa96e10258b5f188e","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/ftplib-pasv.html","https://security-tracker.debian.org/tracker/CVE-2021-4189","https://security.netapp.com/advisory/ntap-20221104-0004/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4189","description":"A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-4189","versionConstraint":"< 3.6.9-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-4189","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"risk":1.598,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-4189"},"relatedVulnerabilities":[{"id":"CVE-2021-4189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"urls":["https://access.redhat.com/security/cve/CVE-2021-4189","https://bugs.python.org/issue43285","https://bugzilla.redhat.com/show_bug.cgi?id=2036020","https://github.com/python/cpython/commit/0ab152c6b5d95caa2dc1a30fa96e10258b5f188e","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/ftplib-pasv.html","https://security-tracker.debian.org/tracker/CVE-2021-4189","https://security.netapp.com/advisory/ntap-20221104-0004/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4189","description":"A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-4189","versionConstraint":"< 3.6.9-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-4189","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"risk":1.598,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-4189"},"relatedVulnerabilities":[{"id":"CVE-2021-4189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"urls":["https://access.redhat.com/security/cve/CVE-2021-4189","https://bugs.python.org/issue43285","https://bugzilla.redhat.com/show_bug.cgi?id=2036020","https://github.com/python/cpython/commit/0ab152c6b5d95caa2dc1a30fa96e10258b5f188e","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/ftplib-pasv.html","https://security-tracker.debian.org/tracker/CVE-2021-4189","https://security.netapp.com/advisory/ntap-20221104-0004/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4189","description":"A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.7"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-4189","versionConstraint":"< 3.6.9-1~18.04ubuntu1.7 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-4189","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.7"],"available":[{"date":"2022-03-28","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.7"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"risk":1.598,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-4189"},"relatedVulnerabilities":[{"id":"CVE-2021-4189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-4189","cwe":"CWE-252","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-4189","date":"2026-10-08","epss":0.03196,"percentile":0.87739}],"urls":["https://access.redhat.com/security/cve/CVE-2021-4189","https://bugs.python.org/issue43285","https://bugzilla.redhat.com/show_bug.cgi?id=2036020","https://github.com/python/cpython/commit/0ab152c6b5d95caa2dc1a30fa96e10258b5f188e","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://python-security.readthedocs.io/vuln/ftplib-pasv.html","https://security-tracker.debian.org/tracker/CVE-2021-4189","https://security.netapp.com/advisory/ntap-20221104-0004/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4189","description":"A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.9+11-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14803","versionConstraint":"< 11.0.9+11-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14803","fix":{"state":"fixed","versions":["11.0.9+11-0ubuntu1~18.04.1"],"available":[{"date":"2020-10-27","kind":"advisory","version":"11.0.9+11-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14803","date":"2026-10-08","epss":0.03186,"percentile":0.87698}],"risk":1.593,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14803"},"relatedVulnerabilities":[{"id":"CVE-2020-14803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14803","date":"2026-10-08","epss":0.03186,"percentile":0.87698}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/10/msg00031.html","https://security.gentoo.org/glsa/202101-19","https://security.netapp.com/advisory/ntap-20201023-0004/","https://www.debian.org/security/2020/dsa-4779","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14803","description":"Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"e268379bae5d9fad","cpes":["cpe:2.3:a:org.springframework.security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-web:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_web:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-security-web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security_web:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:security:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-security-web","purl":"pkg:maven/org.springframework.security/spring-security-web@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.security","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-web-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-security-web","archiveDigests":[{"value":"a9ff06ad3fd66cd08545e1a601c66d2256c86e0f","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-web-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.7.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c4q5-6c82-3qpw","versionConstraint":">=5.0.0,<5.7.13 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.security:spring-security-web","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c4q5-6c82-3qpw","fix":{"state":"fixed","versions":["5.7.13"],"available":[{"date":"2024-10-29","kind":"first-observed","version":"5.7.13"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-38821","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-38821","date":"2026-10-08","epss":0.01741,"percentile":0.77052}],"risk":1.5843099999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-38821","https://spring.io/security/cve-2024-38821","https://github.com/spring-projects/spring-security/commit/0e257b56ce35402558a260ffa6b368982f9a7934","https://github.com/spring-projects/spring-security/commit/4ce7cde15599c0447163fd46bac616e03318bf5b","https://security.netapp.com/advisory/ntap-20250124-0006","https://github.com/spring-projects/spring-security/commit/b4f27777556c157ec5689c0769322c90be984514"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c4q5-6c82-3qpw","description":"Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications"},"relatedVulnerabilities":[{"id":"CVE-2024-38821","cvss":[{"type":"Secondary","source":"security@vmware.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-38821","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-38821","date":"2026-10-08","epss":0.01741,"percentile":0.77052}],"urls":["https://spring.io/security/cve-2024-38821","https://security.netapp.com/advisory/ntap-20250124-0006/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38821","description":"Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances.\n\nFor this to impact an application, all of the following must be true:\n\n  *  It must be a WebFlux application\n  *  It must be using Spring's static resources support\n  *  It must have a non-permitAll authorization rule applied to the static resources support"}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.118"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r29c-68gh-xp6x","versionConstraint":">=8.5.0,<9.0.118 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r29c-68gh-xp6x","fix":{"state":"fixed","versions":["9.0.118"],"available":[{"date":"2026-05-19","kind":"first-observed","version":"9.0.118"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41293","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-41293","date":"2026-10-08","epss":0.0168,"percentile":0.76229}],"risk":1.5792000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-41293","https://lists.apache.org/thread/qwg0q16z7xkb2qrr853wdll5531mvl1r","http://www.openwall.com/lists/oss-security/2026/05/12/13","https://github.com/apache/tomcat/commit/19f17a257797e8d139b33ff9c88d362a273be148","https://github.com/apache/tomcat/commit/1c70480466572c9192ed412ebefcd43fc63137fd","https://github.com/apache/tomcat/commit/2a2476460e823789f530a22207873ea8cd6eff3b","https://github.com/apache/tomcat/commit/3915fd27e6810b14ccd21e3d900bd8faef44d3df","https://github.com/apache/tomcat/commit/57c2b3bfd62792631e1df24cf4237b990a0b36fa","https://github.com/apache/tomcat/commit/c2925554c677da57390f940d856871e18daaacab","https://github.com/apache/tomcat/commit/cf9452443bcbf3b1a4b435ef7d624364f1b65ca3","https://github.com/apache/tomcat/commit/e5cef9618c3f4fd31bd6fb1e83f0f18022280dac","https://github.com/apache/tomcat/commit/f72a6174ab1f0f5a053435f80448b4f6837fe6d7","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-9.html"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r29c-68gh-xp6x","description":"Apache Tomcat - HTTP/2 request headers not validated"},"relatedVulnerabilities":[{"id":"CVE-2026-41293","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41293","cwe":"CWE-20","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-41293","date":"2026-10-08","epss":0.0168,"percentile":0.76229}],"urls":["https://lists.apache.org/thread/qwg0q16z7xkb2qrr853wdll5531mvl1r","http://www.openwall.com/lists/oss-security/2026/05/12/13"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41293","description":"Improper Input Validation vulnerability in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27.\nOlder, end of support versions may also be affected.\n\nUsers are recommended to upgrade to version [FIXED_VERSION], which fixes the issue."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.107"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wr62-c79q-cv37","versionConstraint":">=9.0.0.M1,<9.0.107 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wr62-c79q-cv37","fix":{"state":"fixed","versions":["9.0.107"],"available":[{"date":"2026-03-07","kind":"first-observed","version":"9.0.107"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52520","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-52520","date":"2026-10-08","epss":0.02102,"percentile":0.81149}],"risk":1.5765000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-52520","https://lists.apache.org/thread/trqq01bbxw6c92zx69kx2mw2qgmfy0o5","https://github.com/apache/tomcat/commit/927d66fbc294cb65242102b817a45fd80834e040","https://github.com/apache/tomcat/commit/a51e4bedccfafd35b7cdd0ee3e22267dee9f90db","https://github.com/apache/tomcat/commit/fc42bbccb9041fafd194fbfdf3eab1d44cb5c45c","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html","http://www.openwall.com/lists/oss-security/2025/07/10/12"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wr62-c79q-cv37","description":"Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits"},"relatedVulnerabilities":[{"id":"CVE-2025-52520","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52520","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-52520","date":"2026-10-08","epss":0.02102,"percentile":0.81149}],"urls":["https://lists.apache.org/thread/trqq01bbxw6c92zx69kx2mw2qgmfy0o5","http://www.openwall.com/lists/oss-security/2025/07/10/12","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-52520","description":"For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21277","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21277","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21277","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21277","date":"2026-10-08","epss":0.03091,"percentile":0.87335}],"risk":1.5455,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21277"},"relatedVulnerabilities":[{"id":"CVE-2022-21277","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21277","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21277","date":"2026-10-08","epss":0.03091,"percentile":0.87335}],"urls":["https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21277","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.107"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-25xr-qj8w-c4vf","versionConstraint":">=9.0.0.M1,<9.0.107 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-25xr-qj8w-c4vf","fix":{"state":"fixed","versions":["9.0.107"],"available":[{"date":"2026-03-07","kind":"first-observed","version":"9.0.107"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53506","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-53506","date":"2026-10-08","epss":0.02035,"percentile":0.80491}],"risk":1.52625,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-53506","https://lists.apache.org/thread/p09775q0rd185m6zz98krg0fp45j8kr0","https://github.com/apache/tomcat/commit/2aa6261276ebe50b99276953591e3a2be7898bdb","https://github.com/apache/tomcat/commit/434772930f362145516dd60681134e7f0cf8115b","https://github.com/apache/tomcat/commit/be8f330f83ceddaf3baeed57522e571572b6b99b","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html","http://www.openwall.com/lists/oss-security/2025/07/10/13"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-25xr-qj8w-c4vf","description":"Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams"},"relatedVulnerabilities":[{"id":"CVE-2025-53506","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53506","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-53506","date":"2026-10-08","epss":0.02035,"percentile":0.80491}],"urls":["https://lists.apache.org/thread/p09775q0rd185m6zz98krg0fp45j8kr0","http://www.openwall.com/lists/oss-security/2025/07/10/13","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53506","description":"Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 through 8.5.100. Other EOL versions may also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.8+10-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14556","versionConstraint":"< 11.0.8+10-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14556","fix":{"state":"fixed","versions":["11.0.8+10-0ubuntu1~18.04.1"],"available":[{"date":"2020-07-23","kind":"advisory","version":"11.0.8+10-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14556","date":"2026-10-08","epss":0.03022,"percentile":0.87059}],"risk":1.5110000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14556"},"relatedVulnerabilities":[{"id":"CVE-2020-14556","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14556","date":"2026-10-08","epss":0.03022,"percentile":0.87059}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/","https://security.gentoo.org/glsa/202008-24","https://security.gentoo.org/glsa/202209-15","https://security.netapp.com/advisory/ntap-20200717-0005/","https://usn.ubuntu.com/4433-1/","https://usn.ubuntu.com/4453-1/","https://www.debian.org/security/2020/dsa-4734","https://www.oracle.com/security-alerts/cpujul2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14556","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data as well as unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-22947","versionConstraint":"< 7.58.0-2ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22947","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.15"],"available":[{"date":"2021-09-15","kind":"advisory","version":"7.58.0-2ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22947","cwe":"CWE-310","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22947","cwe":"CWE-345","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22947","date":"2026-10-08","epss":0.03009,"percentile":0.87008}],"risk":1.5045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22947"},"relatedVulnerabilities":[{"id":"CVE-2021-22947","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22947","cwe":"CWE-310","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22947","cwe":"CWE-345","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22947","date":"2026-10-08","epss":0.03009,"percentile":0.87008}],"urls":["http://seclists.org/fulldisclosure/2022/Mar/29","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://hackerone.com/reports/1334763","https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20211029-0003/","https://support.apple.com/kb/HT213183","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22947","description":"When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-22947","versionConstraint":"< 7.58.0-2ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22947","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.15"],"available":[{"date":"2021-09-15","kind":"advisory","version":"7.58.0-2ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22947","cwe":"CWE-310","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22947","cwe":"CWE-345","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22947","date":"2026-10-08","epss":0.03009,"percentile":0.87008}],"risk":1.5045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22947"},"relatedVulnerabilities":[{"id":"CVE-2021-22947","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22947","cwe":"CWE-310","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22947","cwe":"CWE-345","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22947","date":"2026-10-08","epss":0.03009,"percentile":0.87008}],"urls":["http://seclists.org/fulldisclosure/2022/Mar/29","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://hackerone.com/reports/1334763","https://lists.debian.org/debian-lts-announce/2021/09/msg00022.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20211029-0003/","https://support.apple.com/kb/HT213183","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22947","description":"When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-20907","versionConstraint":"< 3.6.9-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-20907","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"risk":1.4925000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-20907"},"relatedVulnerabilities":[{"id":"CVE-2019-20907","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html","https://bugs.python.org/issue39017","https://github.com/python/cpython/pull/21454","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200731-0002/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20907","description":"In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-20907","versionConstraint":"< 3.6.9-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-20907","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"risk":1.4925000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-20907"},"relatedVulnerabilities":[{"id":"CVE-2019-20907","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html","https://bugs.python.org/issue39017","https://github.com/python/cpython/pull/21454","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200731-0002/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20907","description":"In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-20907","versionConstraint":"< 3.6.9-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-20907","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"risk":1.4925000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-20907"},"relatedVulnerabilities":[{"id":"CVE-2019-20907","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html","https://bugs.python.org/issue39017","https://github.com/python/cpython/pull/21454","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200731-0002/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20907","description":"In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-20907","versionConstraint":"< 3.6.9-1~18.04ubuntu1.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-20907","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.1"],"available":[{"date":"2020-07-22","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"risk":1.4925000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-20907"},"relatedVulnerabilities":[{"id":"CVE-2019-20907","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-20907","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-20907","date":"2026-10-08","epss":0.02985,"percentile":0.86903}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html","https://bugs.python.org/issue39017","https://github.com/python/cpython/pull/21454","https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/","https://security.gentoo.org/glsa/202008-01","https://security.netapp.com/advisory/ntap-20200731-0002/","https://usn.ubuntu.com/4428-1/","https://www.oracle.com/security-alerts/cpujan2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20907","description":"In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation."}]},{"artifact":{"id":"d4c86865da6ad268","cpes":["cpe:2.3:a:org.springframework:spring-beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-beans:spring-beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-beans:spring_beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_beans:spring-beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_beans:spring_beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-beans:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_beans:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-beans","purl":"pkg:maven/org.springframework/spring-beans@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-beans-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-beans","archiveDigests":[{"value":"03ae97694618c59e6af695a15e54fabb7e319776","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-beans-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.22.RELEASE"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hh26-6xwr-ggv7","versionConstraint":"<=5.2.21.RELEASE (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-beans","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hh26-6xwr-ggv7","fix":{"state":"fixed","versions":["5.2.22.RELEASE"],"available":[{"date":"2024-02-03","kind":"first-observed","version":"5.2.22.RELEASE"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22970","cwe":"CWE-770","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22970","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22970","date":"2026-10-08","epss":0.01962,"percentile":0.79727}],"risk":1.4714999999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22970","https://tanzu.vmware.com/security/cve-2022-22970","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/spring-projects/spring-framework/commit/83186b689f11f5e6efe7ccc08fdeb92f66fcd583","https://github.com/spring-projects/spring-framework/commit/50177b1ad3485bd44239b1756f6c14607476fcf2","https://security.netapp.com/advisory/ntap-20220616-0006"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hh26-6xwr-ggv7","description":"Denial of service in Spring Framework"},"relatedVulnerabilities":[{"id":"CVE-2022-22970","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:N/I:N/A:P","metrics":{"baseScore":3.5,"impactScore":2.9,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22970","cwe":"CWE-770","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22970","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22970","date":"2026-10-08","epss":0.01962,"percentile":0.79727}],"urls":["https://security.netapp.com/advisory/ntap-20220616-0006/","https://tanzu.vmware.com/security/cve-2022-22970","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22970","description":"In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object."}]},{"artifact":{"id":"100fe9e3e8e98cf6","cpes":["cpe:2.3:a:libonig4:libonig4:6.7.0-1:*:*:*:*:*:*:*"],"name":"libonig4","purl":"pkg:deb/ubuntu/libonig4@6.7.0-1?arch=amd64&distro=ubuntu-18.04&upstream=libonig","type":"deb","version":"6.7.0-1","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libonig4/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libonig4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libonig4:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libonig4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libonig"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19246","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libonig","version":"6.7.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-19246","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-19246","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19246","date":"2026-10-08","epss":0.02942,"percentile":0.86724}],"risk":1.471,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-19246"},"relatedVulnerabilities":[{"id":"CVE-2019-19246","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-19246","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-19246","date":"2026-10-08","epss":0.02942,"percentile":0.86724}],"urls":["https://bugs.php.net/bug.php?id=78559","https://github.com/kkos/oniguruma/commit/d3e402928b6eb3327f8f7d59a9edfa622fec557b","https://lists.debian.org/debian-lts-announce/2019/12/msg00002.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NO267PLHGYZSWX3XTRPKYBKD4J3YOU5V/","https://usn.ubuntu.com/4460-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19246","description":"Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.18"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-27782","versionConstraint":"< 7.58.0-2ubuntu3.18 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-27782","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.18"],"available":[{"date":"2022-05-11","kind":"advisory","version":"7.58.0-2ubuntu3.18"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-27782","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-27782","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-27782","date":"2026-10-08","epss":0.0293,"percentile":0.86676}],"risk":1.465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-27782"},"relatedVulnerabilities":[{"id":"CVE-2022-27782","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27782","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-27782","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-27782","date":"2026-10-08","epss":0.0293,"percentile":0.86676}],"urls":["http://www.openwall.com/lists/oss-security/2023/03/20/6","https://hackerone.com/reports/1555796","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220609-0009/","https://www.debian.org/security/2022/dsa-5197"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27782","description":"libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.18"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27782","versionConstraint":"< 7.58.0-2ubuntu3.18 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-27782","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.18"],"available":[{"date":"2022-05-11","kind":"advisory","version":"7.58.0-2ubuntu3.18"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-27782","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-27782","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-27782","date":"2026-10-08","epss":0.0293,"percentile":0.86676}],"risk":1.465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-27782"},"relatedVulnerabilities":[{"id":"CVE-2022-27782","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27782","cwe":"CWE-840","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-27782","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-27782","date":"2026-10-08","epss":0.0293,"percentile":0.86676}],"urls":["http://www.openwall.com/lists/oss-security/2023/03/20/6","https://hackerone.com/reports/1555796","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://security.gentoo.org/glsa/202212-01","https://security.netapp.com/advisory/ntap-20220609-0009/","https://www.debian.org/security/2022/dsa-5197"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27782","description":"libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily."}]},{"artifact":{"id":"91ad4ea54a8353ff","cpes":["cpe:2.3:a:perl-base:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.26.1-6ubuntu0.3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.26.1-6ubuntu0.3?arch=amd64&distro=ubuntu-18.04&upstream=perl","type":"deb","version":"5.26.1-6ubuntu0.3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","S2P","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.26.1-6ubuntu0.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-10878","versionConstraint":"< 5.26.1-6ubuntu0.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"perl","version":"5.26.1-6ubuntu0.3"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-10878","fix":{"state":"fixed","versions":["5.26.1-6ubuntu0.5"],"available":[{"date":"2020-10-26","kind":"advisory","version":"5.26.1-6ubuntu0.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-10878","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10878","date":"2026-10-08","epss":0.04879,"percentile":0.91837}],"risk":1.4637,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-10878"},"relatedVulnerabilities":[{"id":"CVE-2020-10878","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10878","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10878","date":"2026-10-08","epss":0.04879,"percentile":0.91837}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html","https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod","https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3","https://github.com/perl/perl5/commit/0a320d753fe7fca03df259a4dfd8e641e51edaa8","https://github.com/perl/perl5/commit/3295b48defa0f8570114877b063fe546dd348b3c","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/","https://security.gentoo.org/glsa/202006-03","https://security.netapp.com/advisory/ntap-20200611-0001/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10878","description":"Perl before 5.30.3 has an integer overflow related to mishandling of a \"PL_regkind[OP(n)] == NOTHING\" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.16+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21541","versionConstraint":"< 11.0.16+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21541","fix":{"state":"fixed","versions":["11.0.16+8-0ubuntu1~18.04"],"available":[{"date":"2022-08-04","kind":"advisory","version":"11.0.16+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2022-21541","date":"2026-10-08","epss":0.02906,"percentile":0.86566}],"risk":1.4529999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21541"},"relatedVulnerabilities":[{"id":"CVE-2022-21541","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-21541","date":"2026-10-08","epss":0.02906,"percentile":0.86566}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB/","https://security.gentoo.org/glsa/202401-25","https://security.netapp.com/advisory/ntap-20220729-0009/","https://www.debian.org/security/2022/dsa-5188","https://www.debian.org/security/2022/dsa-5192","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21541","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)."}]},{"artifact":{"id":"2a658e44e9176fca","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.25:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.25","type":"java-archive","version":"1.25","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/snakeyaml-1.25.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"8b6e01ef661d8378ae6dd7b511a7f2a33fae1421","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/snakeyaml-1.25.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.32"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9w3m-gqgf-c4p9","versionConstraint":"<1.32 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.25"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9w3m-gqgf-c4p9","fix":{"state":"fixed","versions":["1.32"],"available":[{"date":"2022-09-15","kind":"first-observed","version":"1.32"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38752","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38752","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38752","date":"2026-10-08","epss":0.02526,"percentile":0.84409}],"risk":1.45245,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-38752","https://bitbucket.org/snakeyaml/snakeyaml/issues/531/stackoverflow-oss-fuzz-47081","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47081","https://security.gentoo.org/glsa/202305-28","https://security.netapp.com/advisory/ntap-20240315-0009"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9w3m-gqgf-c4p9","description":"snakeYAML before 1.32 vulnerable to Denial of Service due to Out-of-bounds Write"},"relatedVulnerabilities":[{"id":"CVE-2022-38752","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38752","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38752","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38752","date":"2026-10-08","epss":0.02526,"percentile":0.84409}],"urls":["https://bitbucket.org/snakeyaml/snakeyaml/issues/531/stackoverflow-oss-fuzz-47081","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47081","https://security.gentoo.org/glsa/202305-28","https://security.netapp.com/advisory/ntap-20240315-0009/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-38752","description":"Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.13+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-35567","versionConstraint":"< 11.0.13+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-35567","fix":{"state":"fixed","versions":["11.0.13+8-0ubuntu1~18.04"],"available":[{"date":"2021-12-17","kind":"advisory","version":"11.0.13+8-0ubuntu1~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2021-35567","date":"2026-10-08","epss":0.02902,"percentile":0.86549}],"risk":1.451,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-35567"},"relatedVulnerabilities":[{"id":"CVE-2021-35567","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:C/I:N/A:N","metrics":{"baseScore":6.3,"impactScore":6.9,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35567","date":"2026-10-08","epss":0.02902,"percentile":0.86549}],"urls":["https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6EUURAQOIJYFZHQ7DFZCO6IKDPIAWTNK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTYZWIXDFUV2H57YQZJWPOD3BC3I3EIQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXTUWAWXVU37GRNIG4TPMA47THO6VAE6/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20211022-0004/","https://www.debian.org/security/2021/dsa-5000","https://www.debian.org/security/2021/dsa-5012","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35567","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via Kerberos to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21291","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21291","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21291","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21291","date":"2026-10-08","epss":0.02896,"percentile":0.86522}],"risk":1.448,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21291"},"relatedVulnerabilities":[{"id":"CVE-2022-21291","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21291","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21291","date":"2026-10-08","epss":0.02896,"percentile":0.86522}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2DIN3L6L3SVZK75CKW2GPSU4HIGZR7XG/","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21291","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"685ff832fa5df143","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23218","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23218","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-08","epss":0.0482,"percentile":0.91745}],"risk":1.446,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23218"},"relatedVulnerabilities":[{"id":"CVE-2022-23218","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-08","epss":0.0482,"percentile":0.91745}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=28768","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23218","description":"The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"71315b6fa75a7166","cpes":["cpe:2.3:a:libc6:libc6:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23218","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23218","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-08","epss":0.0482,"percentile":0.91745}],"risk":1.446,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23218"},"relatedVulnerabilities":[{"id":"CVE-2022-23218","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-08","epss":0.0482,"percentile":0.91745}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=28768","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23218","description":"The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"62a0389fd254614a","cpes":["cpe:2.3:a:locales:locales:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.27-3ubuntu1?arch=all&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23218","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23218","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-08","epss":0.0482,"percentile":0.91745}],"risk":1.446,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23218"},"relatedVulnerabilities":[{"id":"CVE-2022-23218","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-08","epss":0.0482,"percentile":0.91745}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=28768","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23218","description":"The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"6c475aa8af85f1cd","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23218","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23218","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-08","epss":0.0482,"percentile":0.91745}],"risk":1.446,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23218"},"relatedVulnerabilities":[{"id":"CVE-2022-23218","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23218","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23218","date":"2026-10-08","epss":0.0482,"percentile":0.91745}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=28768","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23218","description":"The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21282","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21282","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21282","cwe":"CWE-611","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21282","date":"2026-10-08","epss":0.02877,"percentile":0.86424}],"risk":1.4385000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21282"},"relatedVulnerabilities":[{"id":"CVE-2022-21282","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21282","cwe":"CWE-611","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21282","date":"2026-10-08","epss":0.02877,"percentile":0.86424}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21282","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-25709","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-25709","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.8"],"available":[{"date":"2020-11-17","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-25709","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25709","date":"2026-10-08","epss":0.02858,"percentile":0.8633}],"risk":1.429,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-25709"},"relatedVulnerabilities":[{"id":"CVE-2020-25709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25709","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25709","date":"2026-10-08","epss":0.02858,"percentile":0.8633}],"urls":["http://seclists.org/fulldisclosure/2021/Feb/14","https://bugzilla.redhat.com/show_bug.cgi?id=1899675","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00008.html","https://security.netapp.com/advisory/ntap-20210716-0003/","https://support.apple.com/kb/HT212147","https://www.debian.org/security/2020/dsa-4792"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25709","description":"A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-25709","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-25709","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.8"],"available":[{"date":"2020-11-17","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-25709","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25709","date":"2026-10-08","epss":0.02858,"percentile":0.8633}],"risk":1.429,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-25709"},"relatedVulnerabilities":[{"id":"CVE-2020-25709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25709","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25709","date":"2026-10-08","epss":0.02858,"percentile":0.8633}],"urls":["http://seclists.org/fulldisclosure/2021/Feb/14","https://bugzilla.redhat.com/show_bug.cgi?id=1899675","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00008.html","https://security.netapp.com/advisory/ntap-20210716-0003/","https://support.apple.com/kb/HT212147","https://www.debian.org/security/2020/dsa-4792"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25709","description":"A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"9555badd5b7a08bb","cpes":["cpe:2.3:a:gpgv:gpgv:2.2.4-1ubuntu1.2:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.2.4-1ubuntu1.2?arch=amd64&distro=ubuntu-18.04&upstream=gnupg2","type":"deb","version":"2.2.4-1ubuntu1.2","language":"","licenses":["BSD-3-clause","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.4-1ubuntu1.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-34903","versionConstraint":"< 2.2.4-1ubuntu1.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"gnupg2","version":"2.2.4-1ubuntu1.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-34903","fix":{"state":"fixed","versions":["2.2.4-1ubuntu1.6"],"available":[{"date":"2022-07-05","kind":"advisory","version":"2.2.4-1ubuntu1.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-34903","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-34903","date":"2026-10-08","epss":0.02844,"percentile":0.8627}],"risk":1.422,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-34903"},"relatedVulnerabilities":[{"id":"CVE-2022-34903","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-34903","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-34903","date":"2026-10-08","epss":0.02844,"percentile":0.8627}],"urls":["http://www.openwall.com/lists/oss-security/2022/07/02/1","https://bugs.debian.org/1014157","https://dev.gnupg.org/T6027","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRLWJQ76A4UKHI3Q36BKSJKS4LFLQO33/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPTAR76EIZY7NQFENSOZO7U473257OVZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VN63GBTMRWO36Y7BKA2WQHROAKCXKCBL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU64FUVG2PRZBSHFOQRSP7KDVEIZ23OS/","https://security.netapp.com/advisory/ntap-20220826-0005/","https://www.debian.org/security/2022/dsa-5174","https://www.openwall.com/lists/oss-security/2022/06/30/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-34903","description":"GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line."}]},{"artifact":{"id":"685ff832fa5df143","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9169","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9169","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-08","epss":0.04731,"percentile":0.91614}],"risk":1.4193,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9169"},"relatedVulnerabilities":[{"id":"CVE-2019-9169","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-08","epss":0.04731,"percentile":0.91614}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34140","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34142","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20190315-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=24114","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=583dd860d5b833037175247230a328f0050dbfe9","https://support.f5.com/csp/article/K54823184","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9169","description":"In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match."}]},{"artifact":{"id":"71315b6fa75a7166","cpes":["cpe:2.3:a:libc6:libc6:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9169","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9169","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-08","epss":0.04731,"percentile":0.91614}],"risk":1.4193,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9169"},"relatedVulnerabilities":[{"id":"CVE-2019-9169","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-08","epss":0.04731,"percentile":0.91614}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34140","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34142","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20190315-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=24114","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=583dd860d5b833037175247230a328f0050dbfe9","https://support.f5.com/csp/article/K54823184","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9169","description":"In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match."}]},{"artifact":{"id":"62a0389fd254614a","cpes":["cpe:2.3:a:locales:locales:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.27-3ubuntu1?arch=all&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9169","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9169","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-08","epss":0.04731,"percentile":0.91614}],"risk":1.4193,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9169"},"relatedVulnerabilities":[{"id":"CVE-2019-9169","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-08","epss":0.04731,"percentile":0.91614}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34140","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34142","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20190315-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=24114","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=583dd860d5b833037175247230a328f0050dbfe9","https://support.f5.com/csp/article/K54823184","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9169","description":"In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match."}]},{"artifact":{"id":"6c475aa8af85f1cd","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9169","versionConstraint":"< 2.27-3ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-9169","fix":{"state":"fixed","versions":["2.27-3ubuntu1.2"],"available":[{"date":"2020-07-06","kind":"advisory","version":"2.27-3ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-08","epss":0.04731,"percentile":0.91614}],"risk":1.4193,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-9169"},"relatedVulnerabilities":[{"id":"CVE-2019-9169","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9169","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9169","date":"2026-10-08","epss":0.04731,"percentile":0.91614}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34140","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34142","https://kc.mcafee.com/corporate/index?page=content&id=SB10278","https://security.gentoo.org/glsa/202006-04","https://security.netapp.com/advisory/ntap-20190315-0002/","https://sourceware.org/bugzilla/show_bug.cgi?id=24114","https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=583dd860d5b833037175247230a328f0050dbfe9","https://support.f5.com/csp/article/K54823184","https://usn.ubuntu.com/4416-1/","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9169","description":"In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21296","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21296","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21296","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21296","date":"2026-10-08","epss":0.02825,"percentile":0.86173}],"risk":1.4125,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21296"},"relatedVulnerabilities":[{"id":"CVE-2022-21296","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21296","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21296","date":"2026-10-08","epss":0.02825,"percentile":0.86173}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21296","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"4245af4d1fb8823f","cpes":["cpe:2.3:a:apache:commons-lang:2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_lang:2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:2.6:*:*:*:*:*:*:*"],"name":"commons-lang","purl":"pkg:maven/commons-lang/commons-lang@2.6","type":"java-archive","version":"2.6","language":"java","licenses":[],"metadata":{"pomGroupID":"commons-lang","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/logstash-logback-encoder-5.1.jar:commons-lang:commons-lang","manifestName":"","pomArtifactID":"commons-lang","archiveDigests":null},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/logstash-logback-encoder-5.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j288-q9x7-2f5v","versionConstraint":">=2.0,<=2.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"commons-lang:commons-lang","version":"2.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j288-q9x7-2f5v","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48924","date":"2026-10-08","epss":0.02451,"percentile":0.83897}],"risk":1.409325,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48924","https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","https://github.com/apache/commons-lang/commit/b424803abdb2bec818e4fbcb251ce031c22aca53","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html","http://www.openwall.com/lists/oss-security/2025/07/11/1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j288-q9x7-2f5v","description":"Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs"},"relatedVulnerabilities":[{"id":"CVE-2025-48924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48924","date":"2026-10-08","epss":0.02451,"percentile":0.83897}],"urls":["https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","http://www.openwall.com/lists/oss-security/2025/07/11/1","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48924","description":"Uncontrolled Recursion vulnerability in Apache Commons Lang.\n\nThis issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.\n\nThe methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a \nStackOverflowError could cause an application to stop.\n\nUsers are recommended to upgrade to version 3.18.0, which fixes the issue."}]},{"artifact":{"id":"23a2e51abf50f2f3","cpes":["cpe:2.3:a:apache:commons-lang3:3.7:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_lang3:3.7:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:3.7:*:*:*:*:*:*:*","cpe:2.3:a:apache:lang3:3.7:*:*:*:*:*:*:*"],"name":"commons-lang3","purl":"pkg:maven/org.apache.commons/commons-lang3@3.7","type":"java-archive","version":"3.7","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.apache.commons","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/commons-lang3-3.7.jar","manifestName":"","pomArtifactID":"commons-lang3","archiveDigests":[{"value":"557edd918fd41f9260963583ebf5a61a43a6b423","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/commons-lang3-3.7.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.18.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j288-q9x7-2f5v","versionConstraint":">=3.0,<3.18.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.commons:commons-lang3","version":"3.7"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j288-q9x7-2f5v","fix":{"state":"fixed","versions":["3.18.0"],"available":[{"date":"2025-07-12","kind":"first-observed","version":"3.18.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48924","date":"2026-10-08","epss":0.02451,"percentile":0.83897}],"risk":1.409325,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48924","https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","https://github.com/apache/commons-lang/commit/b424803abdb2bec818e4fbcb251ce031c22aca53","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html","http://www.openwall.com/lists/oss-security/2025/07/11/1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j288-q9x7-2f5v","description":"Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs"},"relatedVulnerabilities":[{"id":"CVE-2025-48924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48924","date":"2026-10-08","epss":0.02451,"percentile":0.83897}],"urls":["https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","http://www.openwall.com/lists/oss-security/2025/07/11/1","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48924","description":"Uncontrolled Recursion vulnerability in Apache Commons Lang.\n\nThis issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.\n\nThe methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a \nStackOverflowError could cause an application to stop.\n\nUsers are recommended to upgrade to version 3.18.0, which fixes the issue."}]},{"artifact":{"id":"3445236446ec4939","cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"krb5-locales","purl":"pkg:deb/ubuntu/krb5-locales@1.16-2ubuntu0.1?arch=all&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-36054","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-36054","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-36054","cwe":"CWE-824","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-36054","date":"2026-10-08","epss":0.02814,"percentile":0.86119}],"risk":1.407,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-36054"},"relatedVulnerabilities":[{"id":"CVE-2023-36054","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-36054","cwe":"CWE-824","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-36054","date":"2026-10-08","epss":0.02814,"percentile":0.86119}],"urls":["https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd","https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final","https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final","https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html","https://security.netapp.com/advisory/ntap-20230908-0004/","https://web.mit.edu/kerberos/www/advisories/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-36054","description":"lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count."}]},{"artifact":{"id":"f3fc35a2cb3401bd","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/ubuntu/libgssapi-krb5-2@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-36054","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-36054","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-36054","cwe":"CWE-824","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-36054","date":"2026-10-08","epss":0.02814,"percentile":0.86119}],"risk":1.407,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-36054"},"relatedVulnerabilities":[{"id":"CVE-2023-36054","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-36054","cwe":"CWE-824","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-36054","date":"2026-10-08","epss":0.02814,"percentile":0.86119}],"urls":["https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd","https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final","https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final","https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html","https://security.netapp.com/advisory/ntap-20230908-0004/","https://web.mit.edu/kerberos/www/advisories/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-36054","description":"lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count."}]},{"artifact":{"id":"ce64c2275844a0e2","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/ubuntu/libk5crypto3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-36054","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-36054","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-36054","cwe":"CWE-824","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-36054","date":"2026-10-08","epss":0.02814,"percentile":0.86119}],"risk":1.407,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-36054"},"relatedVulnerabilities":[{"id":"CVE-2023-36054","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-36054","cwe":"CWE-824","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-36054","date":"2026-10-08","epss":0.02814,"percentile":0.86119}],"urls":["https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd","https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final","https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final","https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html","https://security.netapp.com/advisory/ntap-20230908-0004/","https://web.mit.edu/kerberos/www/advisories/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-36054","description":"lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count."}]},{"artifact":{"id":"a0e77fe46f00e692","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.16-2ubuntu0.1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/ubuntu/libkrb5-3@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-36054","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-36054","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-36054","cwe":"CWE-824","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-36054","date":"2026-10-08","epss":0.02814,"percentile":0.86119}],"risk":1.407,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-36054"},"relatedVulnerabilities":[{"id":"CVE-2023-36054","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-36054","cwe":"CWE-824","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-36054","date":"2026-10-08","epss":0.02814,"percentile":0.86119}],"urls":["https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd","https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final","https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final","https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html","https://security.netapp.com/advisory/ntap-20230908-0004/","https://web.mit.edu/kerberos/www/advisories/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-36054","description":"lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count."}]},{"artifact":{"id":"402827dd4cb6593f","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.16-2ubuntu0.1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/ubuntu/libkrb5support0@1.16-2ubuntu0.1?arch=amd64&distro=ubuntu-18.04&upstream=krb5","type":"deb","version":"1.16-2ubuntu0.1","language":"","licenses":["sha256:f40708d17d90e55eea6e7b50d0e0926b7b675e0e2a98d64eec76873779df9e43"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-36054","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"krb5","version":"1.16-2ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-36054","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-36054","cwe":"CWE-824","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-36054","date":"2026-10-08","epss":0.02814,"percentile":0.86119}],"risk":1.407,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-36054"},"relatedVulnerabilities":[{"id":"CVE-2023-36054","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-36054","cwe":"CWE-824","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-36054","date":"2026-10-08","epss":0.02814,"percentile":0.86119}],"urls":["https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd","https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final","https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final","https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html","https://security.netapp.com/advisory/ntap-20230908-0004/","https://web.mit.edu/kerberos/www/advisories/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-36054","description":"lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-22826","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-22826","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-22826","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22826","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22826","date":"2026-10-08","epss":0.02801,"percentile":0.86057}],"risk":1.4005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-22826"},"relatedVulnerabilities":[{"id":"CVE-2022-22826","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22826","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22826","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22826","date":"2026-10-08","epss":0.02801,"percentile":0.86057}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/539","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22826","description":"nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-22827","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-22827","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-22827","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22827","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22827","date":"2026-10-08","epss":0.02801,"percentile":0.86057}],"risk":1.4005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-22827"},"relatedVulnerabilities":[{"id":"CVE-2022-22827","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22827","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22827","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22827","date":"2026-10-08","epss":0.02801,"percentile":0.86057}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/539","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22827","description":"storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.14+9-0ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21305","versionConstraint":"< 11.0.14+9-0ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21305","fix":{"state":"fixed","versions":["11.0.14+9-0ubuntu2~18.04"],"available":[{"date":"2022-03-07","kind":"advisory","version":"11.0.14+9-0ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21305","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21305","date":"2026-10-08","epss":0.02755,"percentile":0.8582}],"risk":1.3775000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21305"},"relatedVulnerabilities":[{"id":"CVE-2022-21305","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21305","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21305","date":"2026-10-08","epss":0.02755,"percentile":0.8582}],"urls":["https://lists.debian.org/debian-lts-announce/2022/02/msg00011.html","https://security.gentoo.org/glsa/202209-05","https://security.netapp.com/advisory/ntap-20220121-0007/","https://www.debian.org/security/2022/dsa-5057","https://www.debian.org/security/2022/dsa-5058","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21305","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"100fe9e3e8e98cf6","cpes":["cpe:2.3:a:libonig4:libonig4:6.7.0-1:*:*:*:*:*:*:*"],"name":"libonig4","purl":"pkg:deb/ubuntu/libonig4@6.7.0-1?arch=amd64&distro=ubuntu-18.04&upstream=libonig","type":"deb","version":"6.7.0-1","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libonig4/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libonig4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libonig4:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libonig4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libonig"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-16163","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"libonig","version":"6.7.0-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-16163","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-16163","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-16163","date":"2026-10-08","epss":0.02752,"percentile":0.85795}],"risk":1.376,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-16163"},"relatedVulnerabilities":[{"id":"CVE-2019-16163","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-16163","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-16163","date":"2026-10-08","epss":0.02752,"percentile":0.85795}],"urls":["https://github.com/kkos/oniguruma/commit/4097828d7cc87589864fecf452f2cd46c5f37180","https://github.com/kkos/oniguruma/compare/v6.9.2...v6.9.3","https://github.com/kkos/oniguruma/issues/147","https://lists.debian.org/debian-lts-announce/2019/09/msg00010.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NWOWZZNFSAWM3BUTQNAE3PD44A6JU4KE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZW47MSFZ6WYOAOFXHBDGU4LYACFRKC2Y/","https://usn.ubuntu.com/4460-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16163","description":"Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.15+10-0ubuntu0.18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21496","versionConstraint":"< 11.0.15+10-0ubuntu0.18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21496","fix":{"state":"fixed","versions":["11.0.15+10-0ubuntu0.18.04.1"],"available":[{"date":"2022-04-26","kind":"advisory","version":"11.0.15+10-0ubuntu0.18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2022-21496","date":"2026-10-08","epss":0.02752,"percentile":0.8579}],"risk":1.376,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21496"},"relatedVulnerabilities":[{"id":"CVE-2022-21496","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-21496","date":"2026-10-08","epss":0.02752,"percentile":0.8579}],"urls":["https://lists.debian.org/debian-lts-announce/2022/05/msg00017.html","https://security.netapp.com/advisory/ntap-20220429-0006/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2022/dsa-5128","https://www.debian.org/security/2022/dsa-5131","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21496","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"1aef213d2b0dcd29","cpes":["cpe:2.3:a:libfreetype6:libfreetype6:2.8.1-2ubuntu2:*:*:*:*:*:*:*"],"name":"libfreetype6","purl":"pkg:deb/ubuntu/libfreetype6@2.8.1-2ubuntu2?arch=amd64&distro=ubuntu-18.04&upstream=freetype","type":"deb","version":"2.8.1-2ubuntu2","language":"","licenses":["BSD-2-Clause","BSD-3-Clause","Catharon-OSL","FTL","GPL-2","GPL-2+","GZip","OpenGroup-BSD-like"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfreetype6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libfreetype6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"freetype"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.1-2ubuntu2.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27404","versionConstraint":"< 2.8.1-2ubuntu2.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"freetype","version":"2.8.1-2ubuntu2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-27404","fix":{"state":"fixed","versions":["2.8.1-2ubuntu2.2"],"available":[{"date":"2022-07-20","kind":"advisory","version":"2.8.1-2ubuntu2.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-27404","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-27404","date":"2026-10-08","epss":0.02736,"percentile":0.85687}],"risk":1.3679999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-27404"},"relatedVulnerabilities":[{"id":"CVE-2022-27404","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27404","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-27404","date":"2026-10-08","epss":0.02736,"percentile":0.85687}],"urls":["https://gitlab.freedesktop.org/freetype/freetype/-/issues/1138","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EFPNRKDLCXHZVYYQLQMP44UHLU32GA6Z/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FDU2FOEMCEF6WVR6ZBIH5MT5O7FAK6UP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWQ7IB2A75MEHM63WEUXBYEC7OR5SGDY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYVC2NPKKXKP3TWJWG4ONYWNO6ZPHLA5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TCEMWCM46PKM4U5ENRASPKQD6JDOLKRU/","https://security.gentoo.org/glsa/202402-06"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27404","description":"FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.9+11-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14798","versionConstraint":"< 11.0.9+11-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14798","fix":{"state":"fixed","versions":["11.0.9+11-0ubuntu1~18.04.1"],"available":[{"date":"2020-10-27","kind":"advisory","version":"11.0.9+11-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14798","date":"2026-10-08","epss":0.02717,"percentile":0.85586}],"risk":1.3585,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14798"},"relatedVulnerabilities":[{"id":"CVE-2020-14798","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14798","date":"2026-10-08","epss":0.02717,"percentile":0.85586}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/10/msg00031.html","https://security.gentoo.org/glsa/202101-19","https://security.netapp.com/advisory/ntap-20201023-0004/","https://www.debian.org/security/2020/dsa-4779","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14798","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.15+10-0ubuntu0.18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21443","versionConstraint":"< 11.0.15+10-0ubuntu0.18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21443","fix":{"state":"fixed","versions":["11.0.15+10-0ubuntu0.18.04.1"],"available":[{"date":"2022-04-26","kind":"advisory","version":"11.0.15+10-0ubuntu0.18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2022-21443","date":"2026-10-08","epss":0.02717,"percentile":0.85584}],"risk":1.3585,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21443"},"relatedVulnerabilities":[{"id":"CVE-2022-21443","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-21443","date":"2026-10-08","epss":0.02717,"percentile":0.85584}],"urls":["https://lists.debian.org/debian-lts-announce/2022/05/msg00017.html","https://security.netapp.com/advisory/ntap-20220429-0006/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2022/dsa-5128","https://www.debian.org/security/2022/dsa-5131","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21443","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"e2611abd9fd1ccb2","cpes":["cpe:2.3:a:libhogweed4:libhogweed4:3.4-1:*:*:*:*:*:*:*"],"name":"libhogweed4","purl":"pkg:deb/ubuntu/libhogweed4@3.4-1?arch=amd64&distro=ubuntu-18.04&upstream=nettle","type":"deb","version":"3.4-1","language":"","licenses":["GAP","GPL","GPL-2","GPL-2+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1+","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnettle6/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libhogweed4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhogweed4:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libhogweed4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nettle"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.4.1-0ubuntu0.18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3580","versionConstraint":"< 3.4.1-0ubuntu0.18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nettle","version":"3.4-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3580","fix":{"state":"fixed","versions":["3.4.1-0ubuntu0.18.04.1"],"available":[{"date":"2021-06-17","kind":"advisory","version":"3.4.1-0ubuntu0.18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3580","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3580","cwe":"CWE-20","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3580","date":"2026-10-08","epss":0.02708,"percentile":0.85537}],"risk":1.354,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3580"},"relatedVulnerabilities":[{"id":"CVE-2021-3580","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3580","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3580","cwe":"CWE-20","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3580","date":"2026-10-08","epss":0.02708,"percentile":0.85537}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1967983","https://lists.debian.org/debian-lts-announce/2021/09/msg00008.html","https://security.gentoo.org/glsa/202401-24","https://security.netapp.com/advisory/ntap-20211104-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3580","description":"A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service."}]},{"artifact":{"id":"7bf3e2dd1c55781c","cpes":["cpe:2.3:a:libnettle6:libnettle6:3.4-1:*:*:*:*:*:*:*"],"name":"libnettle6","purl":"pkg:deb/ubuntu/libnettle6@3.4-1?arch=amd64&distro=ubuntu-18.04&upstream=nettle","type":"deb","version":"3.4-1","language":"","licenses":["GAP","GPL","GPL-2","GPL-2+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1+","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnettle6/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libnettle6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnettle6:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libnettle6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nettle"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.4.1-0ubuntu0.18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3580","versionConstraint":"< 3.4.1-0ubuntu0.18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nettle","version":"3.4-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-3580","fix":{"state":"fixed","versions":["3.4.1-0ubuntu0.18.04.1"],"available":[{"date":"2021-06-17","kind":"advisory","version":"3.4.1-0ubuntu0.18.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-3580","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3580","cwe":"CWE-20","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3580","date":"2026-10-08","epss":0.02708,"percentile":0.85537}],"risk":1.354,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-3580"},"relatedVulnerabilities":[{"id":"CVE-2021-3580","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3580","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3580","cwe":"CWE-20","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3580","date":"2026-10-08","epss":0.02708,"percentile":0.85537}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1967983","https://lists.debian.org/debian-lts-announce/2021/09/msg00008.html","https://security.gentoo.org/glsa/202401-24","https://security.netapp.com/advisory/ntap-20211104-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3580","description":"A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.14"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-22898","versionConstraint":"< 7.58.0-2ubuntu3.14 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22898","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.14"],"available":[{"date":"2021-07-22","kind":"advisory","version":"7.58.0-2ubuntu3.14"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22898","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22898","cwe":"CWE-909","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22898","date":"2026-10-08","epss":0.04507,"percentile":0.91268}],"risk":1.3521,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22898"},"relatedVulnerabilities":[{"id":"CVE-2021-22898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22898","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22898","cwe":"CWE-909","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22898","date":"2026-10-08","epss":0.04507,"percentile":0.91268}],"urls":["http://www.openwall.com/lists/oss-security/2021/07/21/4","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2021-22898.html","https://github.com/curl/curl/commit/39ce47f219b09c380b81f89fe54ac586c8db6bde","https://hackerone.com/reports/1176461","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POOC3UV7V6L4CJ5KA2PTWTNUV5Y72T3Q/","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://advisory.splunk.com/advisories/SVD-2023-0809","https://curl.se/docs/CVE-2021-22898.json"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22898","description":"curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.14"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-22898","versionConstraint":"< 7.58.0-2ubuntu3.14 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-22898","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.14"],"available":[{"date":"2021-07-22","kind":"advisory","version":"7.58.0-2ubuntu3.14"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-22898","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22898","cwe":"CWE-909","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22898","date":"2026-10-08","epss":0.04507,"percentile":0.91268}],"risk":1.3521,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-22898"},"relatedVulnerabilities":[{"id":"CVE-2021-22898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-22898","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2021-22898","cwe":"CWE-909","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-22898","date":"2026-10-08","epss":0.04507,"percentile":0.91268}],"urls":["http://www.openwall.com/lists/oss-security/2021/07/21/4","https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2021-22898.html","https://github.com/curl/curl/commit/39ce47f219b09c380b81f89fe54ac586c8db6bde","https://hackerone.com/reports/1176461","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html","https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POOC3UV7V6L4CJ5KA2PTWTNUV5Y72T3Q/","https://www.debian.org/security/2022/dsa-5197","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://advisory.splunk.com/advisories/SVD-2023-0809","https://curl.se/docs/CVE-2021-22898.json"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-22898","description":"curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-5678","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-5678","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-5678","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-5678","cwe":"CWE-754","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-5678","date":"2026-10-08","epss":0.04459,"percentile":0.9119}],"risk":1.3377,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-5678"},"relatedVulnerabilities":[{"id":"CVE-2023-5678","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-5678","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-5678","cwe":"CWE-754","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-5678","date":"2026-10-08","epss":0.04459,"percentile":0.9119}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6","https://www.openssl.org/news/secadv/20231106.txt","http://www.openwall.com/lists/oss-security/2024/03/11/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20231130-0010/","https://cert-portal.siemens.com/productcert/html/ssa-093430.html","https://cert-portal.siemens.com/productcert/html/ssa-128433.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-331112.html","https://cert-portal.siemens.com/productcert/html/ssa-341067.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-556635.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-794697.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5678","description":"Issue summary: Generating excessively long X9.42 DH keys or checking\nexcessively long X9.42 DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_generate_key() to\ngenerate an X9.42 DH key may experience long delays.  Likewise, applications\nthat use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check()\nto check an X9.42 DH key or X9.42 DH parameters may experience long delays.\nWhere the key or parameters that are being checked have been obtained from\nan untrusted source this may lead to a Denial of Service.\n\nWhile DH_check() performs all the necessary checks (as of CVE-2023-3817),\nDH_check_pub_key() doesn't make any of these checks, and is therefore\nvulnerable for excessively large P and Q parameters.\n\nLikewise, while DH_generate_key() performs a check for an excessively large\nP, it doesn't check for an excessively large Q.\n\nAn application that calls DH_generate_key() or DH_check_pub_key() and\nsupplies a key or parameters obtained from an untrusted source could be\nvulnerable to a Denial of Service attack.\n\nDH_generate_key() and DH_check_pub_key() are also called by a number of\nother OpenSSL functions.  An application calling any of those other\nfunctions may similarly be affected.  The other functions affected by this\nare DH_check_pub_key_ex(), EVP_PKEY_public_check(), and EVP_PKEY_generate().\n\nAlso vulnerable are the OpenSSL pkey command line application when using the\n\"-pubcheck\" option, as well as the OpenSSL genpkey command line application.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\n\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-5678","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-5678","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-5678","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-5678","cwe":"CWE-754","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-5678","date":"2026-10-08","epss":0.04459,"percentile":0.9119}],"risk":1.3377,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-5678"},"relatedVulnerabilities":[{"id":"CVE-2023-5678","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-5678","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-5678","cwe":"CWE-754","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-5678","date":"2026-10-08","epss":0.04459,"percentile":0.9119}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6","https://www.openssl.org/news/secadv/20231106.txt","http://www.openwall.com/lists/oss-security/2024/03/11/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20231130-0010/","https://cert-portal.siemens.com/productcert/html/ssa-093430.html","https://cert-portal.siemens.com/productcert/html/ssa-128433.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-331112.html","https://cert-portal.siemens.com/productcert/html/ssa-341067.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-556635.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-794697.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5678","description":"Issue summary: Generating excessively long X9.42 DH keys or checking\nexcessively long X9.42 DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_generate_key() to\ngenerate an X9.42 DH key may experience long delays.  Likewise, applications\nthat use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check()\nto check an X9.42 DH key or X9.42 DH parameters may experience long delays.\nWhere the key or parameters that are being checked have been obtained from\nan untrusted source this may lead to a Denial of Service.\n\nWhile DH_check() performs all the necessary checks (as of CVE-2023-3817),\nDH_check_pub_key() doesn't make any of these checks, and is therefore\nvulnerable for excessively large P and Q parameters.\n\nLikewise, while DH_generate_key() performs a check for an excessively large\nP, it doesn't check for an excessively large Q.\n\nAn application that calls DH_generate_key() or DH_check_pub_key() and\nsupplies a key or parameters obtained from an untrusted source could be\nvulnerable to a Denial of Service attack.\n\nDH_generate_key() and DH_check_pub_key() are also called by a number of\nother OpenSSL functions.  An application calling any of those other\nfunctions may similarly be affected.  The other functions affected by this\nare DH_check_pub_key_ex(), EVP_PKEY_public_check(), and EVP_PKEY_generate().\n\nAlso vulnerable are the OpenSSL pkey command line application when using the\n\"-pubcheck\" option, as well as the OpenSSL genpkey command line application.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\n\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.17+8-1ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21619","versionConstraint":"< 11.0.17+8-1ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21619","fix":{"state":"fixed","versions":["11.0.17+8-1ubuntu2~18.04"],"available":[{"date":"2022-11-09","kind":"advisory","version":"11.0.17+8-1ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21619","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21619","date":"2026-10-08","epss":0.02667,"percentile":0.85299}],"risk":1.3335,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21619"},"relatedVulnerabilities":[{"id":"CVE-2022-21619","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21619","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21619","date":"2026-10-08","epss":0.02667,"percentile":0.85299}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/37QDWJBGEPP65X43NXQTXQ7KASLUHON6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ARF4QF4N3X5GSFHXUBWARGLISGKJ33R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QLQ7OD33W6LT3HWI7VYDFFJLV75Y73K/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXSBV3W6EP6B7XJ63Z2FPVBH6HAPGJ5T/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HNGMDNIHAA73BEX6XPA2IMXJSGOKKYE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PB3CIGOFG7CENUVVE4FFZT2HI5FO77XU/","https://security.gentoo.org/glsa/202401-25","https://security.netapp.com/advisory/ntap-20221028-0012/","https://www.oracle.com/security-alerts/cpuoct2022.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21619","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"6a1f2c9983f12362","cpes":["cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4-2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4_2:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.4:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.4-2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.4_2:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-2.4-2","purl":"pkg:deb/ubuntu/libldap-2.4-2@2.4.45%2Bdfsg-1ubuntu1.4?arch=amd64&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.4-2/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-2.4-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-2.4-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-25710","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-25710","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.8"],"available":[{"date":"2020-11-17","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-25710","cwe":"CWE-617","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25710","date":"2026-10-08","epss":0.02666,"percentile":0.85292}],"risk":1.333,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-25710"},"relatedVulnerabilities":[{"id":"CVE-2020-25710","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25710","cwe":"CWE-617","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25710","date":"2026-10-08","epss":0.02666,"percentile":0.85292}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1899678","https://git.openldap.org/openldap/openldap/-/commit/ab3915154e69920d480205b4bf5ccb2b391a0a1f#a2feb6ed0257c21c6672793ee2f94eaadc10c72c","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00008.html","https://security.netapp.com/advisory/ntap-20210716-0003/","https://www.debian.org/security/2020/dsa-4792"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25710","description":"A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"3ae24431b8587800","cpes":["cpe:2.3:a:libldap-common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.4.45\\+dfsg-1ubuntu1.4:*:*:*:*:*:*:*"],"name":"libldap-common","purl":"pkg:deb/ubuntu/libldap-common@2.4.45%2Bdfsg-1ubuntu1.4?arch=all&distro=ubuntu-18.04&upstream=openldap","type":"deb","version":"2.4.45+dfsg-1ubuntu1.4","language":"","licenses":["sha256:0690f1ee382f98e95b446743db55395641d5e258de65939e9cb1c660d67a43a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.45+dfsg-1ubuntu1.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-25710","versionConstraint":"< 2.4.45+dfsg-1ubuntu1.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openldap","version":"2.4.45+dfsg-1ubuntu1.4"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-25710","fix":{"state":"fixed","versions":["2.4.45+dfsg-1ubuntu1.8"],"available":[{"date":"2020-11-17","kind":"advisory","version":"2.4.45+dfsg-1ubuntu1.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-25710","cwe":"CWE-617","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25710","date":"2026-10-08","epss":0.02666,"percentile":0.85292}],"risk":1.333,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-25710"},"relatedVulnerabilities":[{"id":"CVE-2020-25710","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25710","cwe":"CWE-617","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25710","date":"2026-10-08","epss":0.02666,"percentile":0.85292}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1899678","https://git.openldap.org/openldap/openldap/-/commit/ab3915154e69920d480205b4bf5ccb2b391a0a1f#a2feb6ed0257c21c6672793ee2f94eaadc10c72c","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/12/msg00008.html","https://security.netapp.com/advisory/ntap-20210716-0003/","https://www.debian.org/security/2020/dsa-4792"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25710","description":"A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-45061","versionConstraint":"< 3.6.9-1~18.04ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-45061","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.9"],"available":[{"date":"2022-12-08","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-45061","date":"2026-10-08","epss":0.02653,"percentile":0.85219}],"risk":1.3265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-45061"},"relatedVulnerabilities":[{"id":"CVE-2022-45061","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-45061","date":"2026-10-08","epss":0.02653,"percentile":0.85219}],"urls":["https://github.com/python/cpython/issues/98433","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AOUKI72ACV6CHY2QUFO6VK2DNMVJ2MB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/35YDIWCUMWTMDBWFRAVENFH6BLB65D6S/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WBZJNSALFGMPYTINIF57HAAK46U72WQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63FS6VHY4DCS74HBTEINUDOECQ2X6ZCH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WQPHKGNXUJC3TC3BDW5RKGROWRJVSFR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B3YI6JYARWU6GULWOHNUROSACT54XFFS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4MYQ3IV6NWA4CKSXEHW45CH2YNDHEPH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BWJREJHWVRBYDP43YB5WRL3QC7UBA7BR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTPVDZDATRQFE6KAT6B4BQIQ4GRHIIIJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN26PWZTYG6IF3APLRXQJBVACQHZUPT2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCDJXNBHWXNYUTOEV4H2HCFSRKV3SYL3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JTYVESWVBPD57ZJC35G5722Q6TS37WSB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KNE4GMD45RGC2HWUAAIGTDHT5VJ2E4O4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKWAMPURWUV3DCCT4J7VHRF4NT2CFVBR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O67LRHDTJWH544KXB6KY4HMHQLYDXFPK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORVCQGJCCAVLN4DJDTWGREFCUWXKQRML/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PLQ2BNZVBBAQPV3SPRU24ZD37UYJJS7W/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCKD4AFBHXIMHS64ZER2U7QRT33HNE7L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RH57BNT4VQERGEJ5SXNXSVMDYP66YD4H/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTN2OOLKYTG34DODUEJGT5MLC2PFGPBA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3D5TX4TDJPXHXD2QICKTY3OCQC3JARP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHVW73QZJMHA4MK7JBT7CXX7XSNYQEGF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMDX6IFKLOA3NXUQEV524L5LHTPI2JI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3EJ6J7PXVQOULBQZQGBXCXY6LFF6LZD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XXZJL3CNAFS5PAIR7K4RL62S3Y7THR7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPNWZKXPKTNHS5FVMN7UQZ2UPCSEFJUK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB5YCMIRVX35RUB6XPOWKENCVCJEVDRK/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20221209-0007/","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://discuss.python.org/t/python-3-11-1-3-10-9-3-9-16-3-8-16-3-7-16-and-3-12-0-alpha-3-are-now-available/21724"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-45061","description":"An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-45061","versionConstraint":"< 3.6.9-1~18.04ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-45061","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.9"],"available":[{"date":"2022-12-08","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-45061","date":"2026-10-08","epss":0.02653,"percentile":0.85219}],"risk":1.3265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-45061"},"relatedVulnerabilities":[{"id":"CVE-2022-45061","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-45061","date":"2026-10-08","epss":0.02653,"percentile":0.85219}],"urls":["https://github.com/python/cpython/issues/98433","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AOUKI72ACV6CHY2QUFO6VK2DNMVJ2MB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/35YDIWCUMWTMDBWFRAVENFH6BLB65D6S/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WBZJNSALFGMPYTINIF57HAAK46U72WQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63FS6VHY4DCS74HBTEINUDOECQ2X6ZCH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WQPHKGNXUJC3TC3BDW5RKGROWRJVSFR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B3YI6JYARWU6GULWOHNUROSACT54XFFS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4MYQ3IV6NWA4CKSXEHW45CH2YNDHEPH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BWJREJHWVRBYDP43YB5WRL3QC7UBA7BR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTPVDZDATRQFE6KAT6B4BQIQ4GRHIIIJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN26PWZTYG6IF3APLRXQJBVACQHZUPT2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCDJXNBHWXNYUTOEV4H2HCFSRKV3SYL3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JTYVESWVBPD57ZJC35G5722Q6TS37WSB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KNE4GMD45RGC2HWUAAIGTDHT5VJ2E4O4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKWAMPURWUV3DCCT4J7VHRF4NT2CFVBR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O67LRHDTJWH544KXB6KY4HMHQLYDXFPK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORVCQGJCCAVLN4DJDTWGREFCUWXKQRML/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PLQ2BNZVBBAQPV3SPRU24ZD37UYJJS7W/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCKD4AFBHXIMHS64ZER2U7QRT33HNE7L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RH57BNT4VQERGEJ5SXNXSVMDYP66YD4H/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTN2OOLKYTG34DODUEJGT5MLC2PFGPBA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3D5TX4TDJPXHXD2QICKTY3OCQC3JARP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHVW73QZJMHA4MK7JBT7CXX7XSNYQEGF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMDX6IFKLOA3NXUQEV524L5LHTPI2JI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3EJ6J7PXVQOULBQZQGBXCXY6LFF6LZD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XXZJL3CNAFS5PAIR7K4RL62S3Y7THR7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPNWZKXPKTNHS5FVMN7UQZ2UPCSEFJUK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB5YCMIRVX35RUB6XPOWKENCVCJEVDRK/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20221209-0007/","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://discuss.python.org/t/python-3-11-1-3-10-9-3-9-16-3-8-16-3-7-16-and-3-12-0-alpha-3-are-now-available/21724"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-45061","description":"An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-45061","versionConstraint":"< 3.6.9-1~18.04ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-45061","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.9"],"available":[{"date":"2022-12-08","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-45061","date":"2026-10-08","epss":0.02653,"percentile":0.85219}],"risk":1.3265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-45061"},"relatedVulnerabilities":[{"id":"CVE-2022-45061","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-45061","date":"2026-10-08","epss":0.02653,"percentile":0.85219}],"urls":["https://github.com/python/cpython/issues/98433","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AOUKI72ACV6CHY2QUFO6VK2DNMVJ2MB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/35YDIWCUMWTMDBWFRAVENFH6BLB65D6S/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WBZJNSALFGMPYTINIF57HAAK46U72WQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63FS6VHY4DCS74HBTEINUDOECQ2X6ZCH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WQPHKGNXUJC3TC3BDW5RKGROWRJVSFR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B3YI6JYARWU6GULWOHNUROSACT54XFFS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4MYQ3IV6NWA4CKSXEHW45CH2YNDHEPH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BWJREJHWVRBYDP43YB5WRL3QC7UBA7BR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTPVDZDATRQFE6KAT6B4BQIQ4GRHIIIJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN26PWZTYG6IF3APLRXQJBVACQHZUPT2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCDJXNBHWXNYUTOEV4H2HCFSRKV3SYL3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JTYVESWVBPD57ZJC35G5722Q6TS37WSB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KNE4GMD45RGC2HWUAAIGTDHT5VJ2E4O4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKWAMPURWUV3DCCT4J7VHRF4NT2CFVBR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O67LRHDTJWH544KXB6KY4HMHQLYDXFPK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORVCQGJCCAVLN4DJDTWGREFCUWXKQRML/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PLQ2BNZVBBAQPV3SPRU24ZD37UYJJS7W/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCKD4AFBHXIMHS64ZER2U7QRT33HNE7L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RH57BNT4VQERGEJ5SXNXSVMDYP66YD4H/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTN2OOLKYTG34DODUEJGT5MLC2PFGPBA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3D5TX4TDJPXHXD2QICKTY3OCQC3JARP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHVW73QZJMHA4MK7JBT7CXX7XSNYQEGF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMDX6IFKLOA3NXUQEV524L5LHTPI2JI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3EJ6J7PXVQOULBQZQGBXCXY6LFF6LZD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XXZJL3CNAFS5PAIR7K4RL62S3Y7THR7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPNWZKXPKTNHS5FVMN7UQZ2UPCSEFJUK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB5YCMIRVX35RUB6XPOWKENCVCJEVDRK/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20221209-0007/","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://discuss.python.org/t/python-3-11-1-3-10-9-3-9-16-3-8-16-3-7-16-and-3-12-0-alpha-3-are-now-available/21724"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-45061","description":"An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.6.9-1~18.04ubuntu1.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-45061","versionConstraint":"< 3.6.9-1~18.04ubuntu1.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-45061","fix":{"state":"fixed","versions":["3.6.9-1~18.04ubuntu1.9"],"available":[{"date":"2022-12-08","kind":"advisory","version":"3.6.9-1~18.04ubuntu1.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-45061","date":"2026-10-08","epss":0.02653,"percentile":0.85219}],"risk":1.3265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-45061"},"relatedVulnerabilities":[{"id":"CVE-2022-45061","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-45061","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-45061","date":"2026-10-08","epss":0.02653,"percentile":0.85219}],"urls":["https://github.com/python/cpython/issues/98433","https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AOUKI72ACV6CHY2QUFO6VK2DNMVJ2MB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/35YDIWCUMWTMDBWFRAVENFH6BLB65D6S/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WBZJNSALFGMPYTINIF57HAAK46U72WQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63FS6VHY4DCS74HBTEINUDOECQ2X6ZCH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WQPHKGNXUJC3TC3BDW5RKGROWRJVSFR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B3YI6JYARWU6GULWOHNUROSACT54XFFS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4MYQ3IV6NWA4CKSXEHW45CH2YNDHEPH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BWJREJHWVRBYDP43YB5WRL3QC7UBA7BR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTPVDZDATRQFE6KAT6B4BQIQ4GRHIIIJ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN26PWZTYG6IF3APLRXQJBVACQHZUPT2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCDJXNBHWXNYUTOEV4H2HCFSRKV3SYL3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JTYVESWVBPD57ZJC35G5722Q6TS37WSB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KNE4GMD45RGC2HWUAAIGTDHT5VJ2E4O4/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKWAMPURWUV3DCCT4J7VHRF4NT2CFVBR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O67LRHDTJWH544KXB6KY4HMHQLYDXFPK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORVCQGJCCAVLN4DJDTWGREFCUWXKQRML/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PLQ2BNZVBBAQPV3SPRU24ZD37UYJJS7W/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCKD4AFBHXIMHS64ZER2U7QRT33HNE7L/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RH57BNT4VQERGEJ5SXNXSVMDYP66YD4H/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTN2OOLKYTG34DODUEJGT5MLC2PFGPBA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3D5TX4TDJPXHXD2QICKTY3OCQC3JARP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHVW73QZJMHA4MK7JBT7CXX7XSNYQEGF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMDX6IFKLOA3NXUQEV524L5LHTPI2JI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3EJ6J7PXVQOULBQZQGBXCXY6LFF6LZD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XXZJL3CNAFS5PAIR7K4RL62S3Y7THR7O/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPNWZKXPKTNHS5FVMN7UQZ2UPCSEFJUK/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB5YCMIRVX35RUB6XPOWKENCVCJEVDRK/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20221209-0007/","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://discuss.python.org/t/python-3-11-1-3-10-9-3-9-16-3-8-16-3-7-16-and-3-12-0-alpha-3-are-now-available/21724"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-45061","description":"An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.90"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7jqf-v358-p8g7","versionConstraint":">=9.0.13,<9.0.90 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7jqf-v358-p8g7","fix":{"state":"fixed","versions":["9.0.90"],"available":[{"date":"2026-07-01","kind":"first-observed","version":"9.0.90"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-38286","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-38286","date":"2026-10-08","epss":0.0169,"percentile":0.7637}],"risk":1.3224249999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-38286","https://lists.apache.org/thread/wms60cvbsz3fpbz9psxtfx8r41jl6d4s","https://github.com/apache/tomcat/commit/3197862639732e16ec1164557bcd289ebc116c93","https://github.com/apache/tomcat/commit/3344c17cef094da4bb616f4186ed32039627b543","https://github.com/apache/tomcat/commit/76c5cce6f0bcef14b0c21c38910371ca7d322d13","https://security.netapp.com/advisory/ntap-20241101-0010","http://www.openwall.com/lists/oss-security/2024/09/23/2","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7jqf-v358-p8g7","description":"Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-38286","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-38286","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-38286","date":"2026-10-08","epss":0.0169,"percentile":0.7637}],"urls":["https://lists.apache.org/thread/wms60cvbsz3fpbz9psxtfx8r41jl6d4s","http://www.openwall.com/lists/oss-security/2024/09/23/2","https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html","https://security.netapp.com/advisory/ntap-20241101-0010/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38286","description":"Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.\n\n\n\nApache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-22825","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-22825","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-22825","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22825","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22825","date":"2026-10-08","epss":0.02636,"percentile":0.85107}],"risk":1.318,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-22825"},"relatedVulnerabilities":[{"id":"CVE-2022-22825","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22825","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-22825","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-22825","date":"2026-10-08","epss":0.02636,"percentile":0.85107}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/539","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22825","description":"lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow."}]},{"artifact":{"id":"a819527c2e72cbc0","cpes":["cpe:2.3:a:apache:tomcat-embed-websocket:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_websocket:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-websocket","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-websocket-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-websocket","archiveDigests":[{"value":"8d2b93a8621a83d9283a46cae09d8f87bea877fa","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-websocket-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.86"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v682-8vv8-vpwr","versionConstraint":">=9.0.0-M1,<=9.0.85 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-websocket","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-v682-8vv8-vpwr","fix":{"state":"fixed","versions":["9.0.86"],"available":[{"date":"2024-04-12","kind":"first-observed","version":"9.0.86"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-23672","cwe":"CWE-459","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-23672","date":"2026-10-08","epss":0.02313,"percentile":0.82886}],"risk":1.3068449999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-23672","https://lists.apache.org/thread/cmpswfx6tj4s7x0nxxosvfqs11lvdx2f","https://github.com/apache/tomcat/commit/0052b374684b613b0c849899b325ebe334ac6501","https://github.com/apache/tomcat/commit/3631adb1342d8bbd8598802a12b63ad02c37d591","https://github.com/apache/tomcat/commit/52d6650e062d880704898d7d8c1b2b7a3efe8068","https://github.com/apache/tomcat/commit/b0e3b1bd78de270d53e319d7cb79eb282aa53cb9","https://security.netapp.com/advisory/ntap-20240402-0002","https://lists.debian.org/debian-lts-announce/2024/04/msg00001.html","http://www.openwall.com/lists/oss-security/2024/03/13/4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/736G4GPZWS2DSQO5WKXO3G6OMZKFEK55","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UWIS5MMGYDZBLJYT674ZI5AWFHDZ46B"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v682-8vv8-vpwr","description":"Denial of Service via incomplete cleanup vulnerability in Apache Tomcat"},"relatedVulnerabilities":[{"id":"CVE-2024-23672","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-23672","cwe":"CWE-459","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-23672","date":"2026-10-08","epss":0.02313,"percentile":0.82886}],"urls":["https://lists.apache.org/thread/cmpswfx6tj4s7x0nxxosvfqs11lvdx2f","http://www.openwall.com/lists/oss-security/2024/03/13/4","https://lists.debian.org/debian-lts-announce/2024/04/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UWIS5MMGYDZBLJYT674ZI5AWFHDZ46B/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/736G4GPZWS2DSQO5WKXO3G6OMZKFEK55/","https://security.netapp.com/advisory/ntap-20240402-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-23672","description":"Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.\n\nOlder, EOL versions may also be affected.\n\n\nUsers are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue."}]},{"artifact":{"id":"685ff832fa5df143","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23219","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23219","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-08","epss":0.04293,"percentile":0.90869}],"risk":1.2879,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23219"},"relatedVulnerabilities":[{"id":"CVE-2022-23219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-08","epss":0.04293,"percentile":0.90869}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=22542","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23219","description":"The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"71315b6fa75a7166","cpes":["cpe:2.3:a:libc6:libc6:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:112c8cd802eff98eea8d43d694f7df0f264b8166b46ab1bc52c07e3350bac1ba","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23219","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23219","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-08","epss":0.04293,"percentile":0.90869}],"risk":1.2879,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23219"},"relatedVulnerabilities":[{"id":"CVE-2022-23219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-08","epss":0.04293,"percentile":0.90869}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=22542","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23219","description":"The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"62a0389fd254614a","cpes":["cpe:2.3:a:locales:locales:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.27-3ubuntu1?arch=all&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23219","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23219","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-08","epss":0.04293,"percentile":0.90869}],"risk":1.2879,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23219"},"relatedVulnerabilities":[{"id":"CVE-2022-23219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-08","epss":0.04293,"percentile":0.90869}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=22542","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23219","description":"The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"6c475aa8af85f1cd","cpes":["cpe:2.3:a:multiarch-support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch-support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch_support:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch-support:2.27-3ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:multiarch:multiarch_support:2.27-3ubuntu1:*:*:*:*:*:*:*"],"name":"multiarch-support","purl":"pkg:deb/ubuntu/multiarch-support@2.27-3ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=glibc","type":"deb","version":"2.27-3ubuntu1","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/multiarch-support/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/multiarch-support/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/multiarch-support.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/multiarch-support.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.27-3ubuntu1.5"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-23219","versionConstraint":"< 2.27-3ubuntu1.5 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"glibc","version":"2.27-3ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-23219","fix":{"state":"fixed","versions":["2.27-3ubuntu1.5"],"available":[{"date":"2022-03-01","kind":"advisory","version":"2.27-3ubuntu1.5"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-08","epss":0.04293,"percentile":0.90869}],"risk":1.2879,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-23219"},"relatedVulnerabilities":[{"id":"CVE-2022-23219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23219","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23219","date":"2026-10-08","epss":0.04293,"percentile":0.90869}],"urls":["https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","https://security.gentoo.org/glsa/202208-24","https://sourceware.org/bugzilla/show_bug.cgi?id=22542","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23219","description":"The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-45960","versionConstraint":"< 2.2.5-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2021-45960","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.4"],"available":[{"date":"2022-02-21","kind":"advisory","version":"2.2.5-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2021-45960","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-45960","cwe":"CWE-682","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-45960","date":"2026-10-08","epss":0.04234,"percentile":0.90764}],"risk":1.2702,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-45960"},"relatedVulnerabilities":[{"id":"CVE-2021-45960","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-45960","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-45960","cwe":"CWE-682","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-45960","date":"2026-10-08","epss":0.04234,"percentile":0.90764}],"urls":["http://www.openwall.com/lists/oss-security/2022/01/17/3","https://bugzilla.mozilla.org/show_bug.cgi?id=1217609","https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/issues/531","https://github.com/libexpat/libexpat/pull/534","https://security.gentoo.org/glsa/202209-24","https://security.netapp.com/advisory/ntap-20220121-0004/","https://www.debian.org/security/2022/dsa-5073","https://www.tenable.com/security/tns-2022-05"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-45960","description":"In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory)."}]},{"artifact":{"id":"20252e84ccf1b01a","cpes":["cpe:2.3:a:libpython3.6-minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_minimal:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-minimal","purl":"pkg:deb/ubuntu/libpython3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-27043","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-27043","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2023-27043","cwe":"CWE-1286","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-27043","date":"2026-10-08","epss":0.02527,"percentile":0.84422}],"risk":1.2635,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-27043"},"relatedVulnerabilities":[{"id":"CVE-2023-27043","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2023-27043","cwe":"CWE-1286","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-27043","date":"2026-10-08","epss":0.02527,"percentile":0.84422}],"urls":["http://python.org","https://github.com/python/cpython/issues/102988","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SOX7BCN6YL7B3RFPEEXPIU5CMTEHJOKR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/","https://python-security.readthedocs.io/vuln/email-parseaddr-realname.html","https://security.netapp.com/advisory/ntap-20230601-0003/","http://seclists.org/fulldisclosure/2025/Apr/8","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-27043","description":"The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python."}]},{"artifact":{"id":"f30474b24eac6bef","cpes":["cpe:2.3:a:libpython3.6-stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6-stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6_stdlib:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6-stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.6:libpython3.6_stdlib:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"libpython3.6-stdlib","purl":"pkg:deb/ubuntu/libpython3.6-stdlib@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libpython3.6-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libpython3.6-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-27043","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-27043","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2023-27043","cwe":"CWE-1286","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-27043","date":"2026-10-08","epss":0.02527,"percentile":0.84422}],"risk":1.2635,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-27043"},"relatedVulnerabilities":[{"id":"CVE-2023-27043","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2023-27043","cwe":"CWE-1286","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-27043","date":"2026-10-08","epss":0.02527,"percentile":0.84422}],"urls":["http://python.org","https://github.com/python/cpython/issues/102988","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SOX7BCN6YL7B3RFPEEXPIU5CMTEHJOKR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/","https://python-security.readthedocs.io/vuln/email-parseaddr-realname.html","https://security.netapp.com/advisory/ntap-20230601-0003/","http://seclists.org/fulldisclosure/2025/Apr/8","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-27043","description":"The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python."}]},{"artifact":{"id":"5ad0f03a04b97ba5","cpes":["cpe:2.3:a:python3.6:python3.6:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6","purl":"pkg:deb/ubuntu/python3.6@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.list"},{"path":"/var/lib/dpkg/info/python3.6.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.postinst"},{"path":"/var/lib/dpkg/info/python3.6.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-27043","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-27043","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2023-27043","cwe":"CWE-1286","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-27043","date":"2026-10-08","epss":0.02527,"percentile":0.84422}],"risk":1.2635,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-27043"},"relatedVulnerabilities":[{"id":"CVE-2023-27043","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2023-27043","cwe":"CWE-1286","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-27043","date":"2026-10-08","epss":0.02527,"percentile":0.84422}],"urls":["http://python.org","https://github.com/python/cpython/issues/102988","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SOX7BCN6YL7B3RFPEEXPIU5CMTEHJOKR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/","https://python-security.readthedocs.io/vuln/email-parseaddr-realname.html","https://security.netapp.com/advisory/ntap-20230601-0003/","http://seclists.org/fulldisclosure/2025/Apr/8","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-27043","description":"The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python."}]},{"artifact":{"id":"18732fdc0ec4a1df","cpes":["cpe:2.3:a:python3.6-minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6-minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6_minimal:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6-minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*","cpe:2.3:a:python3.6:python3.6_minimal:3.6.9-1\\~18.04ubuntu1:*:*:*:*:*:*:*"],"name":"python3.6-minimal","purl":"pkg:deb/ubuntu/python3.6-minimal@3.6.9-1~18.04ubuntu1?arch=amd64&distro=ubuntu-18.04&upstream=python3.6","type":"deb","version":"3.6.9-1~18.04ubuntu1","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.6-minimal/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/python3.6-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.6-minimal.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.list"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.6-minimal.preinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.6-minimal.prerm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/python3.6-minimal.prerm"}],"upstreams":[{"name":"python3.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-27043","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-27043","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2023-27043","cwe":"CWE-1286","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-27043","date":"2026-10-08","epss":0.02527,"percentile":0.84422}],"risk":1.2635,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-27043"},"relatedVulnerabilities":[{"id":"CVE-2023-27043","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-27043","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2023-27043","cwe":"CWE-1286","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-27043","date":"2026-10-08","epss":0.02527,"percentile":0.84422}],"urls":["http://python.org","https://github.com/python/cpython/issues/102988","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SOX7BCN6YL7B3RFPEEXPIU5CMTEHJOKR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/","https://python-security.readthedocs.io/vuln/email-parseaddr-realname.html","https://security.netapp.com/advisory/ntap-20230601-0003/","http://seclists.org/fulldisclosure/2025/Apr/8","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZAEFSFZDNBNJPNOUTLG5COISGQDLMGV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/75DTHSTNOFFNAWHXKMDXS7EJWC6W2FUC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ARI7VDSNTQVXRQFM6IK5GSSLEIYV4VZH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BQAKLUJMHFGVBRDPEY57BJGNCE5UUPHW/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HXYVPEZUA3465AEFX5JVFVP7KIFZMF3N/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N6M5I6OQHJABNEYY555HUMMKX3Y4P25Z/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NEUNZSZ3CVSM2QWVYH3N2XGOCDWNYUA3/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORLXS5YTKN65E2Q2NWKXMFS5FWQHRNZW/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2MAICLFDDO3QVNHTZ2OCERZQ34R2PIC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2W2BZQIHMCKRI5FNBJERFYMS5PK6TAH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PHVGRKQAGANCSGFI3QMYOCIMS4IFOZA5/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PU6Y2S5CBN5BWCBDAJFTGIBZLK3S2G3J/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDRDDPDN3VFIYXJIYEABY6USX5EU66AG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDDC2VOX7OQC6OHMYTVD4HLFZIV6PYBC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SINP4OVYNB2AGDYI2GS37EMW3H3F7XPZ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZXC32CJ7TWDPJO6GY2XIQRO7JZX5FLP/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWMBD4LNHWEXRI6YVFWJMTJQUL5WOFTS/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YQVY5C5REXWJIORJIL2FIL3ALOEJEF72/","https://cert-portal.siemens.com/productcert/html/ssa-202008.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-27043","description":"The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.16+8-0ubuntu1~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21549","versionConstraint":"< 11.0.16+8-0ubuntu1~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21549","fix":{"state":"fixed","versions":["11.0.16+8-0ubuntu1~18.04"],"available":[{"date":"2022-08-04","kind":"advisory","version":"11.0.16+8-0ubuntu1~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21549","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21549","date":"2026-10-08","epss":0.02523,"percentile":0.84388}],"risk":1.2614999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21549"},"relatedVulnerabilities":[{"id":"CVE-2022-21549","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21549","cwe":"CWE-502","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21549","date":"2026-10-08","epss":0.02523,"percentile":0.84388}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQICCJXXAYMCCXOO24R4W7Q3RSKCYDMX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKJCLA2GDNF4B7ZRKORQ2TIR56AHJ4VC/","https://security.gentoo.org/glsa/202401-25","https://security.netapp.com/advisory/ntap-20220729-0009/","https://www.debian.org/security/2022/dsa-5192","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21549","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.3.1; Oracle GraalVM Enterprise Edition: 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.22"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-43552","versionConstraint":"< 7.58.0-2ubuntu3.22 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-43552","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.22"],"available":[{"date":"2023-01-05","kind":"advisory","version":"7.58.0-2ubuntu3.22"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-43552","date":"2026-10-08","epss":0.02511,"percentile":0.84298}],"risk":1.2555,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-43552"},"relatedVulnerabilities":[{"id":"CVE-2022-43552","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-43552","date":"2026-10-08","epss":0.02511,"percentile":0.84298}],"urls":["http://seclists.org/fulldisclosure/2023/Mar/17","https://hackerone.com/reports/1764858","https://security.gentoo.org/glsa/202310-12","https://security.netapp.com/advisory/ntap-20230214-0002/","https://support.apple.com/kb/HT213670"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-43552","description":"A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.22"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-43552","versionConstraint":"< 7.58.0-2ubuntu3.22 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-43552","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.22"],"available":[{"date":"2023-01-05","kind":"advisory","version":"7.58.0-2ubuntu3.22"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-43552","date":"2026-10-08","epss":0.02511,"percentile":0.84298}],"risk":1.2555,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-43552"},"relatedVulnerabilities":[{"id":"CVE-2022-43552","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-43552","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-43552","date":"2026-10-08","epss":0.02511,"percentile":0.84298}],"urls":["http://seclists.org/fulldisclosure/2023/Mar/17","https://hackerone.com/reports/1764858","https://security.gentoo.org/glsa/202310-12","https://security.netapp.com/advisory/ntap-20230214-0002/","https://support.apple.com/kb/HT213670"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-43552","description":"A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path."}]},{"artifact":{"id":"3f92c454a30427fb","cpes":["cpe:2.3:a:org.springframework:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-webmvc:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_webmvc:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_webmvc:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-webmvc","purl":"pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":["Apache-2.0","BSD-3-Clause"],"metadata":{"pomGroupID":"org.springframework","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-webmvc-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-webmvc","archiveDigests":[{"value":"652abc943904d67504dc822197868cafaa5e56b5","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-webmvc-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7pm4-g2qj-j85x","versionConstraint":">=5.2.0,<5.2.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework:spring-webmvc","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7pm4-g2qj-j85x","fix":{"state":"fixed","versions":["5.2.3"],"available":[{"date":"2020-07-28","kind":"first-observed","version":"5.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-5397","cwe":"CWE-352","type":"Secondary","source":"security@pivotal.io"},{"cve":"CVE-2020-5397","cwe":"CWE-352","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-5397","date":"2026-10-08","epss":0.02428,"percentile":0.83738}],"risk":1.25042,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-5397","https://pivotal.io/security/cve-2020-5397","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/spring-projects/spring-framework","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/spring-projects/spring-framework/commit/bc7d01048579430b4b2df668178809b63d3f1929"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7pm4-g2qj-j85x","description":"CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux"},"relatedVulnerabilities":[{"id":"CVE-2020-5397","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security@pivotal.io","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-5397","cwe":"CWE-352","type":"Secondary","source":"security@pivotal.io"},{"cve":"CVE-2020-5397","cwe":"CWE-352","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-5397","date":"2026-10-08","epss":0.02428,"percentile":0.83738}],"urls":["https://pivotal.io/security/cve-2020-5397","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-5397","description":"Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.19+7~us1-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-21939","versionConstraint":"< 11.0.19+7~us1-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2023-21939","fix":{"state":"fixed","versions":["11.0.19+7~us1-0ubuntu1~18.04.1"],"available":[{"date":"2023-05-16","kind":"advisory","version":"11.0.19+7~us1-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2023-21939","date":"2026-10-08","epss":0.02495,"percentile":0.84196}],"risk":1.2475,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-21939"},"relatedVulnerabilities":[{"id":"CVE-2023-21939","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-21939","date":"2026-10-08","epss":0.02495,"percentile":0.84196}],"urls":["https://lists.debian.org/debian-lts-announce/2023/09/msg00018.html","https://security.netapp.com/advisory/ntap-20230427-0008/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.couchbase.com/alerts/","https://www.debian.org/security/2023/dsa-5430","https://www.debian.org/security/2023/dsa-5478","https://www.oracle.com/security-alerts/cpuapr2023.html","https://openjdk.org/groups/vulnerability/advisories/2023-04-18"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-21939","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing).  Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and  22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.9+11-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14796","versionConstraint":"< 11.0.9+11-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14796","fix":{"state":"fixed","versions":["11.0.9+11-0ubuntu1~18.04.1"],"available":[{"date":"2020-10-27","kind":"advisory","version":"11.0.9+11-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14796","date":"2026-10-08","epss":0.02493,"percentile":0.84189}],"risk":1.2465,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14796"},"relatedVulnerabilities":[{"id":"CVE-2020-14796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14796","date":"2026-10-08","epss":0.02493,"percentile":0.84189}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/10/msg00031.html","https://security.gentoo.org/glsa/202101-19","https://security.netapp.com/advisory/ntap-20201023-0004/","https://www.debian.org/security/2020/dsa-4779","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14796","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.118"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h6fc-48rj-7qqh","versionConstraint":"<9.0.118 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h6fc-48rj-7qqh","fix":{"state":"fixed","versions":["9.0.118"],"available":[{"date":"2026-05-19","kind":"first-observed","version":"9.0.118"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43512","cwe":"CWE-592","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-43512","date":"2026-10-08","epss":0.01326,"percentile":0.70119}],"risk":1.24644,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-43512","https://lists.apache.org/thread/7x09x7o12solvclslw3sz0288xc8wx73","http://www.openwall.com/lists/oss-security/2026/05/12/8","https://github.com/apache/tomcat/commit/3d4d3fae07a6cd9c2eb193c5491001740ec64448","https://github.com/apache/tomcat/commit/6565a6cb6499e56fe2f34457cec99f9d1c4f39e9","https://github.com/apache/tomcat/commit/a99c355e8199adbfd67c9a1fffbd85b810b196cd","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-11.html","https://tomcat.apache.org/security-9.html"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h6fc-48rj-7qqh","description":"Apache Tomcat - Digest authenticator will authenticate any unknown user"},"relatedVulnerabilities":[{"id":"CVE-2026-43512","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43512","cwe":"CWE-592","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-43512","date":"2026-10-08","epss":0.01326,"percentile":0.70119}],"urls":["https://lists.apache.org/thread/7x09x7o12solvclslw3sz0288xc8wx73","http://www.openwall.com/lists/oss-security/2026/05/12/8"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43512","description":"DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0.\nOlder unsupported versions any also be affect\n\nUsers are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.15+10-0ubuntu0.18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21434","versionConstraint":"< 11.0.15+10-0ubuntu0.18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21434","fix":{"state":"fixed","versions":["11.0.15+10-0ubuntu0.18.04.1"],"available":[{"date":"2022-04-26","kind":"advisory","version":"11.0.15+10-0ubuntu0.18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2022-21434","date":"2026-10-08","epss":0.02492,"percentile":0.8418}],"risk":1.246,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21434"},"relatedVulnerabilities":[{"id":"CVE-2022-21434","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-21434","date":"2026-10-08","epss":0.02492,"percentile":0.8418}],"urls":["https://lists.debian.org/debian-lts-announce/2022/05/msg00017.html","https://security.netapp.com/advisory/ntap-20220429-0006/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.debian.org/security/2022/dsa-5128","https://www.debian.org/security/2022/dsa-5131","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21434","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"c67e239bf70af34c","cpes":["cpe:2.3:a:libasn1-8-heimdal:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8-heimdal:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8_heimdal:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8_heimdal:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1-8:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1_8:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1:libasn1-8-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libasn1:libasn1_8_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libasn1-8-heimdal","purl":"pkg:deb/ubuntu/libasn1-8-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libasn1-8-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libasn1-8-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasn1-8-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libasn1-8-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16860","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-16860","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.1"],"available":[{"date":"2022-10-13","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"risk":1.243,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16860"},"relatedVulnerabilities":[{"id":"CVE-2018-16860","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6,"impactScore":6.5,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html","http://seclists.org/fulldisclosure/2019/Aug/11","http://seclists.org/fulldisclosure/2019/Aug/13","http://seclists.org/fulldisclosure/2019/Aug/14","http://seclists.org/fulldisclosure/2019/Aug/15","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","https://seclists.org/bugtraq/2019/Aug/21","https://seclists.org/bugtraq/2019/Aug/22","https://seclists.org/bugtraq/2019/Aug/23","https://seclists.org/bugtraq/2019/Aug/25","https://security.gentoo.org/glsa/202003-52","https://support.apple.com/HT210346","https://support.apple.com/HT210348","https://support.apple.com/HT210351","https://support.apple.com/HT210353","https://www.samba.org/samba/security/CVE-2018-16860.html","https://www.synology.com/security/advisory/Synology_SA_19_23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16860","description":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal."}]},{"artifact":{"id":"489fa43422e60874","cpes":["cpe:2.3:a:libgssapi3-heimdal:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3-heimdal:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3_heimdal:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3_heimdal:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3:libgssapi3-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi3:libgssapi3_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libgssapi3-heimdal","purl":"pkg:deb/ubuntu/libgssapi3-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi3-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libgssapi3-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi3-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libgssapi3-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16860","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-16860","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.1"],"available":[{"date":"2022-10-13","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"risk":1.243,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16860"},"relatedVulnerabilities":[{"id":"CVE-2018-16860","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6,"impactScore":6.5,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html","http://seclists.org/fulldisclosure/2019/Aug/11","http://seclists.org/fulldisclosure/2019/Aug/13","http://seclists.org/fulldisclosure/2019/Aug/14","http://seclists.org/fulldisclosure/2019/Aug/15","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","https://seclists.org/bugtraq/2019/Aug/21","https://seclists.org/bugtraq/2019/Aug/22","https://seclists.org/bugtraq/2019/Aug/23","https://seclists.org/bugtraq/2019/Aug/25","https://security.gentoo.org/glsa/202003-52","https://support.apple.com/HT210346","https://support.apple.com/HT210348","https://support.apple.com/HT210351","https://support.apple.com/HT210353","https://www.samba.org/samba/security/CVE-2018-16860.html","https://www.synology.com/security/advisory/Synology_SA_19_23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16860","description":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal."}]},{"artifact":{"id":"8af38808136cd0ba","cpes":["cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4_heimdal:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4_heimdal:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4:libhcrypto4-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhcrypto4:libhcrypto4_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libhcrypto4-heimdal","purl":"pkg:deb/ubuntu/libhcrypto4-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libhcrypto4-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libhcrypto4-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhcrypto4-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libhcrypto4-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16860","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-16860","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.1"],"available":[{"date":"2022-10-13","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"risk":1.243,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16860"},"relatedVulnerabilities":[{"id":"CVE-2018-16860","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6,"impactScore":6.5,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html","http://seclists.org/fulldisclosure/2019/Aug/11","http://seclists.org/fulldisclosure/2019/Aug/13","http://seclists.org/fulldisclosure/2019/Aug/14","http://seclists.org/fulldisclosure/2019/Aug/15","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","https://seclists.org/bugtraq/2019/Aug/21","https://seclists.org/bugtraq/2019/Aug/22","https://seclists.org/bugtraq/2019/Aug/23","https://seclists.org/bugtraq/2019/Aug/25","https://security.gentoo.org/glsa/202003-52","https://support.apple.com/HT210346","https://support.apple.com/HT210348","https://support.apple.com/HT210351","https://support.apple.com/HT210353","https://www.samba.org/samba/security/CVE-2018-16860.html","https://www.synology.com/security/advisory/Synology_SA_19_23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16860","description":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal."}]},{"artifact":{"id":"4fe49c3e8d200f83","cpes":["cpe:2.3:a:libheimbase1-heimdal:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1-heimdal:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1_heimdal:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1_heimdal:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1:libheimbase1-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimbase1:libheimbase1_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libheimbase1-heimdal","purl":"pkg:deb/ubuntu/libheimbase1-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheimbase1-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libheimbase1-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheimbase1-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libheimbase1-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16860","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-16860","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.1"],"available":[{"date":"2022-10-13","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"risk":1.243,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16860"},"relatedVulnerabilities":[{"id":"CVE-2018-16860","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6,"impactScore":6.5,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html","http://seclists.org/fulldisclosure/2019/Aug/11","http://seclists.org/fulldisclosure/2019/Aug/13","http://seclists.org/fulldisclosure/2019/Aug/14","http://seclists.org/fulldisclosure/2019/Aug/15","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","https://seclists.org/bugtraq/2019/Aug/21","https://seclists.org/bugtraq/2019/Aug/22","https://seclists.org/bugtraq/2019/Aug/23","https://seclists.org/bugtraq/2019/Aug/25","https://security.gentoo.org/glsa/202003-52","https://support.apple.com/HT210346","https://support.apple.com/HT210348","https://support.apple.com/HT210351","https://support.apple.com/HT210353","https://www.samba.org/samba/security/CVE-2018-16860.html","https://www.synology.com/security/advisory/Synology_SA_19_23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16860","description":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal."}]},{"artifact":{"id":"5ac1d9d8c3d94a69","cpes":["cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0_heimdal:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0_heimdal:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0:libheimntlm0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libheimntlm0:libheimntlm0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libheimntlm0-heimdal","purl":"pkg:deb/ubuntu/libheimntlm0-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheimntlm0-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libheimntlm0-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheimntlm0-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libheimntlm0-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16860","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-16860","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.1"],"available":[{"date":"2022-10-13","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"risk":1.243,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16860"},"relatedVulnerabilities":[{"id":"CVE-2018-16860","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6,"impactScore":6.5,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html","http://seclists.org/fulldisclosure/2019/Aug/11","http://seclists.org/fulldisclosure/2019/Aug/13","http://seclists.org/fulldisclosure/2019/Aug/14","http://seclists.org/fulldisclosure/2019/Aug/15","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","https://seclists.org/bugtraq/2019/Aug/21","https://seclists.org/bugtraq/2019/Aug/22","https://seclists.org/bugtraq/2019/Aug/23","https://seclists.org/bugtraq/2019/Aug/25","https://security.gentoo.org/glsa/202003-52","https://support.apple.com/HT210346","https://support.apple.com/HT210348","https://support.apple.com/HT210351","https://support.apple.com/HT210353","https://www.samba.org/samba/security/CVE-2018-16860.html","https://www.synology.com/security/advisory/Synology_SA_19_23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16860","description":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal."}]},{"artifact":{"id":"5aedfa9521e17f6a","cpes":["cpe:2.3:a:libhx509-5-heimdal:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5-heimdal:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5_heimdal:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5_heimdal:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509-5:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509_5:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509:libhx509-5-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libhx509:libhx509_5_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libhx509-5-heimdal","purl":"pkg:deb/ubuntu/libhx509-5-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libhx509-5-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libhx509-5-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhx509-5-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libhx509-5-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16860","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-16860","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.1"],"available":[{"date":"2022-10-13","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"risk":1.243,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16860"},"relatedVulnerabilities":[{"id":"CVE-2018-16860","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6,"impactScore":6.5,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html","http://seclists.org/fulldisclosure/2019/Aug/11","http://seclists.org/fulldisclosure/2019/Aug/13","http://seclists.org/fulldisclosure/2019/Aug/14","http://seclists.org/fulldisclosure/2019/Aug/15","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","https://seclists.org/bugtraq/2019/Aug/21","https://seclists.org/bugtraq/2019/Aug/22","https://seclists.org/bugtraq/2019/Aug/23","https://seclists.org/bugtraq/2019/Aug/25","https://security.gentoo.org/glsa/202003-52","https://support.apple.com/HT210346","https://support.apple.com/HT210348","https://support.apple.com/HT210351","https://support.apple.com/HT210353","https://www.samba.org/samba/security/CVE-2018-16860.html","https://www.synology.com/security/advisory/Synology_SA_19_23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16860","description":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal."}]},{"artifact":{"id":"ec3f5f14c892446a","cpes":["cpe:2.3:a:libkrb5-26-heimdal:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26-heimdal:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26_heimdal:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26_heimdal:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-26:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_26:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-26-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_26_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libkrb5-26-heimdal","purl":"pkg:deb/ubuntu/libkrb5-26-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-26-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libkrb5-26-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-26-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libkrb5-26-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16860","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-16860","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.1"],"available":[{"date":"2022-10-13","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"risk":1.243,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16860"},"relatedVulnerabilities":[{"id":"CVE-2018-16860","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6,"impactScore":6.5,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html","http://seclists.org/fulldisclosure/2019/Aug/11","http://seclists.org/fulldisclosure/2019/Aug/13","http://seclists.org/fulldisclosure/2019/Aug/14","http://seclists.org/fulldisclosure/2019/Aug/15","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","https://seclists.org/bugtraq/2019/Aug/21","https://seclists.org/bugtraq/2019/Aug/22","https://seclists.org/bugtraq/2019/Aug/23","https://seclists.org/bugtraq/2019/Aug/25","https://security.gentoo.org/glsa/202003-52","https://support.apple.com/HT210346","https://support.apple.com/HT210348","https://support.apple.com/HT210351","https://support.apple.com/HT210353","https://www.samba.org/samba/security/CVE-2018-16860.html","https://www.synology.com/security/advisory/Synology_SA_19_23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16860","description":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal."}]},{"artifact":{"id":"d29c0be392861a2d","cpes":["cpe:2.3:a:libroken18-heimdal:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18-heimdal:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18_heimdal:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18_heimdal:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18:libroken18-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libroken18:libroken18_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libroken18-heimdal","purl":"pkg:deb/ubuntu/libroken18-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libroken18-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libroken18-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libroken18-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libroken18-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16860","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-16860","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.1"],"available":[{"date":"2022-10-13","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"risk":1.243,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16860"},"relatedVulnerabilities":[{"id":"CVE-2018-16860","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6,"impactScore":6.5,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html","http://seclists.org/fulldisclosure/2019/Aug/11","http://seclists.org/fulldisclosure/2019/Aug/13","http://seclists.org/fulldisclosure/2019/Aug/14","http://seclists.org/fulldisclosure/2019/Aug/15","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","https://seclists.org/bugtraq/2019/Aug/21","https://seclists.org/bugtraq/2019/Aug/22","https://seclists.org/bugtraq/2019/Aug/23","https://seclists.org/bugtraq/2019/Aug/25","https://security.gentoo.org/glsa/202003-52","https://support.apple.com/HT210346","https://support.apple.com/HT210348","https://support.apple.com/HT210351","https://support.apple.com/HT210353","https://www.samba.org/samba/security/CVE-2018-16860.html","https://www.synology.com/security/advisory/Synology_SA_19_23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16860","description":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal."}]},{"artifact":{"id":"4c95d1ed3ad0ede5","cpes":["cpe:2.3:a:libwind0-heimdal:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0-heimdal:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0_heimdal:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0_heimdal:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0:libwind0-heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:libwind0:libwind0_heimdal:7.5.0\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libwind0-heimdal","purl":"pkg:deb/ubuntu/libwind0-heimdal@7.5.0%2Bdfsg-1?arch=amd64&distro=ubuntu-18.04&upstream=heimdal","type":"deb","version":"7.5.0+dfsg-1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libwind0-heimdal/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libwind0-heimdal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libwind0-heimdal:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libwind0-heimdal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"heimdal"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.0+dfsg-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16860","versionConstraint":"< 7.5.0+dfsg-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"heimdal","version":"7.5.0+dfsg-1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2018-16860","fix":{"state":"fixed","versions":["7.5.0+dfsg-1ubuntu0.1"],"available":[{"date":"2022-10-13","kind":"advisory","version":"7.5.0+dfsg-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"risk":1.243,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-16860"},"relatedVulnerabilities":[{"id":"CVE-2018-16860","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6,"impactScore":6.5,"exploitabilityScore":6.9},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-16860","cwe":"CWE-358","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16860","date":"2026-10-08","epss":0.02486,"percentile":0.8414}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html","http://seclists.org/fulldisclosure/2019/Aug/11","http://seclists.org/fulldisclosure/2019/Aug/13","http://seclists.org/fulldisclosure/2019/Aug/14","http://seclists.org/fulldisclosure/2019/Aug/15","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","https://seclists.org/bugtraq/2019/Aug/21","https://seclists.org/bugtraq/2019/Aug/22","https://seclists.org/bugtraq/2019/Aug/23","https://seclists.org/bugtraq/2019/Aug/25","https://security.gentoo.org/glsa/202003-52","https://support.apple.com/HT210346","https://support.apple.com/HT210348","https://support.apple.com/HT210351","https://support.apple.com/HT210353","https://www.samba.org/samba/security/CVE-2018-16860.html","https://www.synology.com/security/advisory/Synology_SA_19_23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16860","description":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal."}]},{"artifact":{"id":"d5ffa0f3f5e11c5b","cpes":["cpe:2.3:a:org.hibernate.validator.hibernate-validator:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.validator.hibernate-validator:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.validator.hibernate-validator:validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.validator:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.validator:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-validator:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-validator:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_validator:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_validator:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.validator:validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-validator:validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_validator:validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:validator:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:validator:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:validator:validator:6.0.17.Final:*:*:*:*:*:*:*"],"name":"hibernate-validator","purl":"pkg:maven/org.hibernate.validator/hibernate-validator@6.0.17.Final","type":"java-archive","version":"6.0.17.Final","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.hibernate.validator","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/hibernate-validator-6.0.17.Final.jar","manifestName":"","pomArtifactID":"hibernate-validator","archiveDigests":[{"value":"0af73055fc4a103ab347c56e7da5a143d68a0170","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/hibernate-validator-6.0.17.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"6.0.18.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m8p2-495h-ccmh","versionConstraint":">=6.0.0.Alpha1,<=6.0.17.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.hibernate.validator:hibernate-validator","version":"6.0.17.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-m8p2-495h-ccmh","fix":{"state":"fixed","versions":["6.0.18.Final"],"available":[{"date":"2025-08-12","kind":"first-observed","version":"6.0.18.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-10219","cwe":"CWE-79","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-10219","cwe":"CWE-79","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10219","date":"2026-10-08","epss":0.02157,"percentile":0.81632}],"risk":1.2402749999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-10219","https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219","https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fe","https://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6@%3Cnotifications.accumulo.apache.org%3E","https://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d@%3Cnotifications.accumulo.apache.org%3E","https://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf@%3Cnotifications.accumulo.apache.org%3E","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4@%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a@%3Cpluto-dev.portals.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2022.html","https://security.netapp.com/advisory/ntap-20220210-0024","https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf%40%3Cnotifications.accumulo.apache.org%3E","https://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d%40%3Cnotifications.accumulo.apache.org%3E","https://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6%40%3Cnotifications.accumulo.apache.org%3E","https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Origin/CVE-2019-10219/exploit","https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-10219","https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56cee"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m8p2-495h-ccmh","description":"The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks"},"relatedVulnerabilities":[{"id":"CVE-2019-10219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-10219","cwe":"CWE-79","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2019-10219","cwe":"CWE-79","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-10219","date":"2026-10-08","epss":0.02157,"percentile":0.81632}],"urls":["https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219","https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56cee","https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fe","https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-10219","https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Origin/CVE-2019-10219/exploit","https://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6%40%3Cnotifications.accumulo.apache.org%3E","https://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d%40%3Cnotifications.accumulo.apache.org%3E","https://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf%40%3Cnotifications.accumulo.apache.org%3E","https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3E","https://security.netapp.com/advisory/ntap-20220210-0024/","https://www.oracle.com/security-alerts/cpujan2022.html","https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-10219","description":"A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack."}]},{"artifact":{"id":"7dc697ce703ba421","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.2.5-3ubuntu0.2:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.2.5-3ubuntu0.2?arch=amd64&distro=ubuntu-18.04&upstream=expat","type":"deb","version":"2.2.5-3ubuntu0.2","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.2.5-3ubuntu0.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-43680","versionConstraint":"< 2.2.5-3ubuntu0.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"expat","version":"2.2.5-3ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-43680","fix":{"state":"fixed","versions":["2.2.5-3ubuntu0.8"],"available":[{"date":"2022-11-17","kind":"advisory","version":"2.2.5-3ubuntu0.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-43680","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-43680","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-43680","date":"2026-10-08","epss":0.02457,"percentile":0.83939}],"risk":1.2285000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-43680"},"relatedVulnerabilities":[{"id":"CVE-2022-43680","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-43680","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-43680","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-43680","date":"2026-10-08","epss":0.02457,"percentile":0.83939}],"urls":["http://www.openwall.com/lists/oss-security/2023/12/28/5","http://www.openwall.com/lists/oss-security/2024/01/03/5","https://github.com/libexpat/libexpat/issues/649","https://github.com/libexpat/libexpat/pull/616","https://github.com/libexpat/libexpat/pull/650","https://lists.debian.org/debian-lts-announce/2022/10/msg00033.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJ5VY2VYXE4WTRGQ6LMGLF6FV3SY37YE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BY4OPSIB33ETNUXZY2UPZ4NGQ3OKDY4D/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPQVIF6TOJNY2T3ZZETFKR4G34FFREBQ/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFCOMBSOJKLIKCGCJWHLJXO4EVYBG7AR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUJ2BULJTZ2BMSKQHB6US674P55UCWWS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XG5XOOB7CD55CEE6OJYKSACSIMQ4RWQ6/","https://security.gentoo.org/glsa/202210-38","https://security.netapp.com/advisory/ntap-20221118-0007/","https://www.debian.org/security/2022/dsa-5266"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-43680","description":"In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations."}]},{"artifact":{"id":"5d52c6da56f9d4a6","cpes":["cpe:2.3:a:org.hibernate.orm.core:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.orm.core:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-core:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-core:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_core:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_core:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-org:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-org:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_org:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_org:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.orm.core:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.orm.core:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:core:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:core:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-core:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_core:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-core:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-org:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_core:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_org:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:orm:hibernate-core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:orm:hibernate_core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-org:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_org:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:core:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:core:orm:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:orm:core:5.4.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:orm:orm:5.4.6.Final:*:*:*:*:*:*:*"],"name":"hibernate-core","purl":"pkg:maven/org.hibernate/hibernate-core@5.4.6.Final","type":"java-archive","version":"5.4.6.Final","language":"java","licenses":[],"metadata":{"pomGroupID":"org.hibernate","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/hibernate-core-5.4.6.Final.jar","manifestName":"","pomArtifactID":"hibernate-core","archiveDigests":[{"value":"a319fdf00595c7e29fba31ef23b4a58fbe333f47","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/hibernate-core-5.4.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.18"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8grg-q944-cch5","versionConstraint":">=5.4.0,<5.4.18 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.hibernate:hibernate-core","version":"5.4.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8grg-q944-cch5","fix":{"state":"fixed","versions":["5.4.18"],"available":[{"date":"2024-06-28","kind":"first-observed","version":"5.4.18"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14900","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14900","date":"2026-10-08","epss":0.02126,"percentile":0.81359}],"risk":1.2224499999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2019-14900","https://bugzilla.redhat.com/show_bug.cgi?id=1666499","https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44@%3Cdev.turbine.apache.org%3E","https://github.com/hibernate/hibernate-orm/commit/3f3c1ab50604ab9ba99e25d2016fb85f3ba9dcd4","https://github.com/hibernate/hibernate-orm/commit/646b383f959eff18d58081b1a574f0d777d353da","https://github.com/hibernate/hibernate-orm/commit/e0e22ea256c1906235d6a8e90b79c4ce33d0861f","https://github.com/hibernate/hibernate-orm/commit/eebf01fbf3c2550ee70cdc9c1b02b52e330c8c36","https://security.netapp.com/advisory/ntap-20220210-0020"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8grg-q944-cch5","description":"SQL Injection in Hibernate ORM"},"relatedVulnerabilities":[{"id":"CVE-2019-14900","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14900","cwe":"CWE-89","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14900","date":"2026-10-08","epss":0.02126,"percentile":0.81359}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1666499","https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44%40%3Cdev.turbine.apache.org%3E","https://security.netapp.com/advisory/ntap-20220210-0020/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14900","description":"A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks."}]},{"artifact":{"id":"d5ffa0f3f5e11c5b","cpes":["cpe:2.3:a:org.hibernate.validator.hibernate-validator:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.validator.hibernate-validator:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.validator.hibernate-validator:validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.validator:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.validator:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-validator:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-validator:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_validator:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_validator:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:org.hibernate.validator:validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate-validator:validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate_validator:validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:validator:hibernate-validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:validator:hibernate_validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:hibernate:validator:6.0.17.Final:*:*:*:*:*:*:*","cpe:2.3:a:validator:validator:6.0.17.Final:*:*:*:*:*:*:*"],"name":"hibernate-validator","purl":"pkg:maven/org.hibernate.validator/hibernate-validator@6.0.17.Final","type":"java-archive","version":"6.0.17.Final","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.hibernate.validator","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/hibernate-validator-6.0.17.Final.jar","manifestName":"","pomArtifactID":"hibernate-validator","archiveDigests":[{"value":"0af73055fc4a103ab347c56e7da5a143d68a0170","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/hibernate-validator-6.0.17.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"6.0.20.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rmrm-75hp-phr2","versionConstraint":"<=6.0.19.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.hibernate.validator:hibernate-validator","version":"6.0.17.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rmrm-75hp-phr2","fix":{"state":"fixed","versions":["6.0.20.Final"],"available":[{"date":"2021-06-05","kind":"first-observed","version":"6.0.20.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10693","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-10693","cwe":"CWE-20","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10693","date":"2026-10-08","epss":0.02351,"percentile":0.8319}],"risk":1.2107649999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10693","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10693","https://www.ibm.com/support/pages/node/6348216","https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4@%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c@%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a@%3Cpluto-dev.portals.apache.org%3E","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rmrm-75hp-phr2","description":"Improper Input Validation in Hibernate Validator"},"relatedVulnerabilities":[{"id":"CVE-2020-10693","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-10693","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-10693","cwe":"CWE-20","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-10693","date":"2026-10-08","epss":0.02351,"percentile":0.8319}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10693","https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3E","https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3E","https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3E","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-10693","description":"A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages."}]},{"artifact":{"id":"fe0e460326107a0f","cpes":["cpe:2.3:a:libcups2:libcups2:2.2.7-1ubuntu2.7:*:*:*:*:*:*:*"],"name":"libcups2","purl":"pkg:deb/ubuntu/libcups2@2.2.7-1ubuntu2.7?arch=amd64&distro=ubuntu-18.04&upstream=cups","type":"deb","version":"2.2.7-1ubuntu2.7","language":"","licenses":["BSD-2-clause","GPL-2","GPL-2.0","LGPL-2","LGPL-2.0","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-35235","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"cups","version":"2.2.7-1ubuntu2.7"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2024-35235","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-35235","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-35235","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-35235","date":"2026-10-08","epss":0.02421,"percentile":0.83683}],"risk":1.2105,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-35235"},"relatedVulnerabilities":[{"id":"CVE-2024-35235","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-35235","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-35235","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-35235","date":"2026-10-08","epss":0.02421,"percentile":0.83683}],"urls":["http://www.openwall.com/lists/oss-security/2024/06/11/1","http://www.openwall.com/lists/oss-security/2024/06/12/4","http://www.openwall.com/lists/oss-security/2024/06/12/5","https://git.launchpad.net/ubuntu/+source/apparmor/tree/profiles/apparmor.d/abstractions/user-tmp#n21","https://github.com/OpenPrinting/cups/blob/aba917003c8de55e5bf85010f0ecf1f1ddd1408e/cups/http-addr.c#L229-L240","https://github.com/OpenPrinting/cups/commit/ff1f8a623e090dee8a8aadf12a6a4b25efac143d","https://github.com/OpenPrinting/cups/security/advisories/GHSA-vvwp-mv6j-hw6f","https://lists.debian.org/debian-lts-announce/2024/06/msg00001.html","http://www.openwall.com/lists/oss-security/2024/11/08/3","https://github.com/OpenPrinting/cups/releases/tag/v2.4.9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35235","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group (not root) command execution could be achieved, which can further be used on Ubuntu systems to achieve full root command execution. Commit ff1f8a623e090dee8a8aadf12a6a4b25efac143d contains a patch for the issue."}]},{"artifact":{"id":"13a9ac46d72c9ab7","cpes":["cpe:2.3:a:unzip:unzip:6.0-21ubuntu1:*:*:*:*:*:*:*"],"name":"unzip","purl":"pkg:deb/ubuntu/unzip@6.0-21ubuntu1?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"6.0-21ubuntu1","language":"","licenses":["sha256:e4864130ae7765aa9424f558ca7ca8fa01c1674344ab83e4ceec749ccda76980"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/unzip/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/unzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/unzip.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/unzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/unzip.list","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/unzip.list"},{"path":"/var/lib/dpkg/info/unzip.postinst","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/unzip.postinst"},{"path":"/var/lib/dpkg/info/unzip.postrm","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/unzip.postrm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.0-21ubuntu1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-0529","versionConstraint":"< 6.0-21ubuntu1.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"unzip","version":"6.0-21ubuntu1"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-0529","fix":{"state":"fixed","versions":["6.0-21ubuntu1.2"],"available":[{"date":"2022-10-13","kind":"advisory","version":"6.0-21ubuntu1.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-0529","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0529","date":"2026-10-08","epss":0.02421,"percentile":0.83682}],"risk":1.2105,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-0529"},"relatedVulnerabilities":[{"id":"CVE-2022-0529","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0529","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0529","date":"2026-10-08","epss":0.02421,"percentile":0.83682}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2051395","https://github.com/ByteHackr/unzip_poc","https://lists.debian.org/debian-lts-announce/2022/09/msg00028.html","https://security.gentoo.org/glsa/202310-17","https://www.debian.org/security/2022/dsa-5202"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0529","description":"A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution."}]},{"artifact":{"id":"8e62788fd0d03826","cpes":["cpe:2.3:a:org.springframework.security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:org.springframework.security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security-core:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security_core:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring-security-core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security_core:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring-security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring_security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:springframework:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:security:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:spring:security:5.2.0.RELEASE:*:*:*:*:*:*:*","cpe:2.3:a:vmware:security:5.2.0.RELEASE:*:*:*:*:*:*:*"],"name":"spring-security-core","purl":"pkg:maven/org.springframework.security/spring-security-core@5.2.0.RELEASE","type":"java-archive","version":"5.2.0.RELEASE","language":"java","licenses":[],"metadata":{"pomGroupID":"org.springframework.security","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-core-5.2.0.RELEASE.jar","manifestName":"","pomArtifactID":"spring-security-core","archiveDigests":[{"value":"1c8f36e316a74c245073ce2a70bdf198a58424f6","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/spring-security-core-5.2.0.RELEASE.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.5.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wx54-3278-m5g4","versionConstraint":">=5.2.0.RELEASE,<5.5.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.springframework.security:spring-security-core","version":"5.2.0.RELEASE"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wx54-3278-m5g4","fix":{"state":"fixed","versions":["5.5.7"],"available":[{"date":"2022-05-26","kind":"first-observed","version":"5.5.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22976","cwe":"CWE-190","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22976","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22976","date":"2026-10-08","epss":0.02344,"percentile":0.83131}],"risk":1.20716,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22976","https://tanzu.vmware.com/security/cve-2022-22976","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/spring-projects/spring-security/commit/388a7b62b906bd56deadb7ca45248fa1a63bdf12","https://github.com/spring-projects/spring-security/commit/a40f73521c0dd88b879ff6165d280e78bdf8154f","https://security.netapp.com/advisory/ntap-20220707-0003"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wx54-3278-m5g4","description":"Integer overflow in BCrypt class in Spring Security"},"relatedVulnerabilities":[{"id":"CVE-2022-22976","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-22976","cwe":"CWE-190","type":"Secondary","source":"security@vmware.com"},{"cve":"CVE-2022-22976","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-22976","date":"2026-10-08","epss":0.02344,"percentile":0.83131}],"urls":["https://security.netapp.com/advisory/ntap-20220707-0003/","https://tanzu.vmware.com/security/cve-2022-22976","https://www.oracle.com/security-alerts/cpujul2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-22976","description":"Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE."}]},{"artifact":{"id":"2a658e44e9176fca","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.25:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.25:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.25","type":"java-archive","version":"1.25","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/snakeyaml-1.25.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"8b6e01ef661d8378ae6dd7b511a7f2a33fae1421","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/snakeyaml-1.25.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c4r9-r8fh-9vj2","versionConstraint":"<1.31 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.25"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c4r9-r8fh-9vj2","fix":{"state":"fixed","versions":["1.31"],"available":[{"date":"2022-09-16","kind":"first-observed","version":"1.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38749","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38749","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38749","date":"2026-10-08","epss":0.02061,"percentile":0.80751}],"risk":1.1850749999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-38749","https://bitbucket.org/snakeyaml/snakeyaml/issues/525/got-stackoverflowerror-for-many-open","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47024","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.gentoo.org/glsa/202305-28","https://arxiv.org/pdf/2306.05534.pdf","https://security.netapp.com/advisory/ntap-20240315-0010"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c4r9-r8fh-9vj2","description":"snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write"},"relatedVulnerabilities":[{"id":"CVE-2022-38749","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38749","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38749","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38749","date":"2026-10-08","epss":0.02061,"percentile":0.80751}],"urls":["https://bitbucket.org/snakeyaml/snakeyaml/issues/525/got-stackoverflowerror-for-many-open","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47024","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.gentoo.org/glsa/202305-28","https://security.netapp.com/advisory/ntap-20240315-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-38749","description":"Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.68"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p22x-g9px-3945","versionConstraint":">=9.0.0-M1,<9.0.68 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p22x-g9px-3945","fix":{"state":"fixed","versions":["9.0.68"],"available":[{"date":"2024-04-24","kind":"first-observed","version":"9.0.68"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42252","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2022-42252","cwe":"CWE-444","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42252","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42252","date":"2026-10-08","epss":0.01575,"percentile":0.74696}],"risk":1.18125,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-42252","https://lists.apache.org/thread/zzcxzvqfdqn515zfs3dxb7n8gty589sq","https://security.gentoo.org/glsa/202305-37","https://github.com/apache/tomcat/commit/0d089a15047faf9cb3c82f80f4d28febd4798920","https://github.com/apache/tomcat/commit/4c7f4fd09d2cc1692112ef70b8ee23a7a037ae77","https://github.com/apache/tomcat/commit/a1c07906d8dcaf7957e5cc97f5cdbac7d18a205a","https://github.com/apache/tomcat/commit/c9fe754e5d17e262dfbd3eab2a03ca96ff372dc3","https://tomcat.apache.org/security-10.html","https://tomcat.apache.org/security-8.html","https://tomcat.apache.org/security-9.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p22x-g9px-3945","description":"Apache Tomcat may reject request containing invalid Content-Length header"},"relatedVulnerabilities":[{"id":"CVE-2022-42252","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-42252","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2022-42252","cwe":"CWE-444","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-42252","cwe":"CWE-444","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-42252","date":"2026-10-08","epss":0.01575,"percentile":0.74696}],"urls":["https://lists.apache.org/thread/zzcxzvqfdqn515zfs3dxb7n8gty589sq","https://security.gentoo.org/glsa/202305-37"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-42252","description":"If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header."}]},{"artifact":{"id":"7202c38a8fadd202","cpes":["cpe:2.3:a:apache:tomcat-embed-core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat_embed_core:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:embed:9.0.27:*:*:*:*:*:*:*"],"name":"tomcat-embed-core","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.27","type":"java-archive","version":"9.0.27","language":"java","licenses":["Apache-2.0","CDDL-1.0"],"metadata":{"pomGroupID":"org.apache.tomcat.embed","virtualPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","manifestName":"","pomArtifactID":"tomcat-embed-core","archiveDigests":[{"value":"f1bb28625eb8e10ba05081ec840f49a2ea520d85","algorithm":"sha1"}]},"locations":[{"path":"/app/hydra2/lib/core-2.19.6-exec.jar","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/app/hydra2/lib/core-2.19.6-exec.jar:BOOT-INF/lib/tomcat-embed-core-9.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.0.107"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4j3c-42xv-3f84","versionConstraint":">=9.0.0.M1,<9.0.107 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","version":"9.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4j3c-42xv-3f84","fix":{"state":"fixed","versions":["9.0.107"],"available":[{"date":"2026-07-01","kind":"first-observed","version":"9.0.107"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52434","cwe":"CWE-362","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-52434","date":"2026-10-08","epss":0.01983,"percentile":0.79937}],"risk":1.179885,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-52434","https://lists.apache.org/thread/gxgh65004f25y8519coth6w7vchww030","https://github.com/apache/tomcat/commit/8a83c3c42d20762782678932c14005cd3397a018","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html","http://www.openwall.com/lists/oss-security/2025/07/10/11"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4j3c-42xv-3f84","description":"Apache Tomcat is vulnerable to resource exhaustion when using the APR/Native connector"},"relatedVulnerabilities":[{"id":"CVE-2025-52434","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52434","cwe":"CWE-362","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-52434","date":"2026-10-08","epss":0.01983,"percentile":0.79937}],"urls":["https://lists.apache.org/thread/gxgh65004f25y8519coth6w7vchww030","http://www.openwall.com/lists/oss-security/2025/07/10/11","https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-52434","description":"Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.\n\nThis issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nUsers are recommended to upgrade to version 9.0.107, which fixes the issue."}]},{"artifact":{"id":"13e5904e4425c8fe","cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.35-2ubuntu2.7:*:*:*:*:*:*:*"],"name":"libnss3","purl":"pkg:deb/ubuntu/libnss3@2%3A3.35-2ubuntu2.7?arch=amd64&distro=ubuntu-18.04&upstream=nss","type":"deb","version":"2:3.35-2ubuntu2.7","language":"","licenses":["HPND","HPND-sell-variant","MIT","MPL-2.0","Zlib","blessing"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nss"}]},"matchDetails":[{"fix":{"suggestedVersion":"2:3.35-2ubuntu2.14"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-25648","versionConstraint":"< 2:3.35-2ubuntu2.14 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"nss","version":"2:3.35-2ubuntu2.7"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-25648","fix":{"state":"fixed","versions":["2:3.35-2ubuntu2.14"],"available":[{"date":"2022-05-11","kind":"advisory","version":"2:3.35-2ubuntu2.14"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-25648","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-25648","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25648","date":"2026-10-08","epss":0.03901,"percentile":0.89997}],"risk":1.1703,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-25648"},"relatedVulnerabilities":[{"id":"CVE-2020-25648","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25648","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2020-25648","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-25648","date":"2026-10-08","epss":0.03901,"percentile":0.89997}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1887319","https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.58_release_notes","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://lists.debian.org/debian-lts-announce/2023/10/msg00039.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ERA5SVJQXQMDGES7RIT4F4NQVLD35RXN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRM53IQCPZT2US3M7JXTP6I6IBA5RGOD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RPOLN6DJUYQ3QBQEGLZGV73SNIPK7GHV/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25648","description":"A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58."}]},{"artifact":{"id":"9bda4b0a6e327c0a","cpes":["cpe:2.3:a:curl:curl:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-8284","versionConstraint":"< 7.58.0-2ubuntu3.12 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8284","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.12"],"available":[{"date":"2020-12-09","kind":"advisory","version":"7.58.0-2ubuntu3.12"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8284","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"}],"epss":[{"cve":"CVE-2020-8284","date":"2026-10-08","epss":0.03898,"percentile":0.89989}],"risk":1.1694,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8284"},"relatedVulnerabilities":[{"id":"CVE-2020-8284","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8284","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"}],"epss":[{"cve":"CVE-2020-8284","date":"2026-10-08","epss":0.03898,"percentile":0.89989}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2020-8284.html","https://hackerone.com/reports/1040166","https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/","https://security.gentoo.org/glsa/202012-14","https://security.netapp.com/advisory/ntap-20210122-0007/","https://support.apple.com/kb/HT212325","https://support.apple.com/kb/HT212326","https://support.apple.com/kb/HT212327","https://www.debian.org/security/2021/dsa-4881","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8284","description":"A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions."}]},{"artifact":{"id":"ed3c7019bffd143d","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.58.0-2ubuntu3.8:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/ubuntu/libcurl4@7.58.0-2ubuntu3.8?arch=amd64&distro=ubuntu-18.04&upstream=curl","type":"deb","version":"7.58.0-2ubuntu3.8","language":"","licenses":["BSD-3-Clause","BSD-4-Clause","ISC","curl","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"7.58.0-2ubuntu3.12"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-8284","versionConstraint":"< 7.58.0-2ubuntu3.12 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"curl","version":"7.58.0-2ubuntu3.8"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-8284","fix":{"state":"fixed","versions":["7.58.0-2ubuntu3.12"],"available":[{"date":"2020-12-09","kind":"advisory","version":"7.58.0-2ubuntu3.12"}]},"cvss":[],"cwes":[{"cve":"CVE-2020-8284","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"}],"epss":[{"cve":"CVE-2020-8284","date":"2026-10-08","epss":0.03898,"percentile":0.89989}],"risk":1.1694,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-8284"},"relatedVulnerabilities":[{"id":"CVE-2020-8284","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8284","cwe":"CWE-200","type":"Secondary","source":"support@hackerone.com"}],"epss":[{"cve":"CVE-2020-8284","date":"2026-10-08","epss":0.03898,"percentile":0.89989}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://curl.se/docs/CVE-2020-8284.html","https://hackerone.com/reports/1040166","https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/","https://security.gentoo.org/glsa/202012-14","https://security.netapp.com/advisory/ntap-20210122-0007/","https://support.apple.com/kb/HT212325","https://support.apple.com/kb/HT212326","https://support.apple.com/kb/HT212327","https://www.debian.org/security/2021/dsa-4881","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8284","description":"A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.9+11-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14781","versionConstraint":"< 11.0.9+11-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14781","fix":{"state":"fixed","versions":["11.0.9+11-0ubuntu1~18.04.1"],"available":[{"date":"2020-10-27","kind":"advisory","version":"11.0.9+11-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14781","date":"2026-10-08","epss":0.02324,"percentile":0.82969}],"risk":1.162,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14781"},"relatedVulnerabilities":[{"id":"CVE-2020-14781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14781","date":"2026-10-08","epss":0.02324,"percentile":0.82969}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/10/msg00031.html","https://security.gentoo.org/glsa/202101-19","https://security.netapp.com/advisory/ntap-20201023-0004/","https://www.debian.org/security/2020/dsa-4779","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14781","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.17+8-1ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21628","versionConstraint":"< 11.0.17+8-1ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21628","fix":{"state":"fixed","versions":["11.0.17+8-1ubuntu2~18.04"],"available":[{"date":"2022-11-09","kind":"advisory","version":"11.0.17+8-1ubuntu2~18.04"}]},"cvss":[],"epss":[{"cve":"CVE-2022-21628","date":"2026-10-08","epss":0.02307,"percentile":0.8283}],"risk":1.1535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21628"},"relatedVulnerabilities":[{"id":"CVE-2022-21628","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-21628","date":"2026-10-08","epss":0.02307,"percentile":0.8283}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/37QDWJBGEPP65X43NXQTXQ7KASLUHON6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ARF4QF4N3X5GSFHXUBWARGLISGKJ33R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QLQ7OD33W6LT3HWI7VYDFFJLV75Y73K/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXSBV3W6EP6B7XJ63Z2FPVBH6HAPGJ5T/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HNGMDNIHAA73BEX6XPA2IMXJSGOKKYE6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PB3CIGOFG7CENUVVE4FFZT2HI5FO77XU/","https://security.gentoo.org/glsa/202401-25","https://security.netapp.com/advisory/ntap-20221028-0012/","https://www.oracle.com/security-alerts/cpuoct2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21628","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}]},{"artifact":{"id":"ce188dc97dd90a60","cpes":["cpe:2.3:a:libssl1.1:libssl1.1:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"libssl1.1","purl":"pkg:deb/ubuntu/libssl1.1@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04&upstream=openssl","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/libssl1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/libssl1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1563","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1563","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.6"],"available":[{"date":"2020-05-28","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1563","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-1563","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1563","date":"2026-10-08","epss":0.03838,"percentile":0.89841}],"risk":1.1513999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1563"},"relatedVulnerabilities":[{"id":"CVE-2019-1563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1563","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-1563","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1563","date":"2026-10-08","epss":0.03838,"percentile":0.89841}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00054.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00072.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00012.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00016.html","http://packetstormsecurity.com/files/154467/Slackware-Security-Advisory-openssl-Updates.html","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=08229ad838c50f644d7e928e2eef147b4308ad64","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=631f94db0065c78181ca9ba5546ebc8bb3884b97","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e21f8cf78a125cd3c8c0d1a1a6c8bb0b901f893f","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://lists.debian.org/debian-lts-announce/2019/09/msg00026.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/","https://seclists.org/bugtraq/2019/Oct/0","https://seclists.org/bugtraq/2019/Oct/1","https://seclists.org/bugtraq/2019/Sep/25","https://security.gentoo.org/glsa/201911-04","https://security.netapp.com/advisory/ntap-20190919-0002/","https://support.f5.com/csp/article/K97324400?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4376-1/","https://usn.ubuntu.com/4376-2/","https://usn.ubuntu.com/4504-1/","https://www.debian.org/security/2019/dsa-4539","https://www.debian.org/security/2019/dsa-4540","https://www.openssl.org/news/secadv/20190910.txt","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.tenable.com/security/tns-2019-09"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1563","description":"In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s)."}]},{"artifact":{"id":"c409ac4f6459941a","cpes":["cpe:2.3:a:openssl:openssl:1.1.1-1ubuntu2.1\\~18.04.5:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@1.1.1-1ubuntu2.1~18.04.5?arch=amd64&distro=ubuntu-18.04","type":"deb","version":"1.1.1-1ubuntu2.1~18.04.5","language":"","licenses":["OpenSSL"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl1.1/copyright","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:72dcdf5c21571fd3f2bf3904c34e70a3ff2106ccd60aeb7dda4b7bd631d10af1","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.1-1ubuntu2.1~18.04.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-1563","versionConstraint":"< 1.1.1-1ubuntu2.1~18.04.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.5"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2019-1563","fix":{"state":"fixed","versions":["1.1.1-1ubuntu2.1~18.04.6"],"available":[{"date":"2020-05-28","kind":"advisory","version":"1.1.1-1ubuntu2.1~18.04.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2019-1563","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-1563","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1563","date":"2026-10-08","epss":0.03838,"percentile":0.89841}],"risk":1.1513999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-1563"},"relatedVulnerabilities":[{"id":"CVE-2019-1563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1563","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-1563","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1563","date":"2026-10-08","epss":0.03838,"percentile":0.89841}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00054.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00072.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00012.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00016.html","http://packetstormsecurity.com/files/154467/Slackware-Security-Advisory-openssl-Updates.html","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=08229ad838c50f644d7e928e2eef147b4308ad64","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=631f94db0065c78181ca9ba5546ebc8bb3884b97","https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e21f8cf78a125cd3c8c0d1a1a6c8bb0b901f893f","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://lists.debian.org/debian-lts-announce/2019/09/msg00026.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GY6SNRJP2S7Y42GIIDO3HXPNMDYN2U3A/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZN4VVQJ3JDCHGIHV4Y2YTXBYQZ6PWQ7E/","https://seclists.org/bugtraq/2019/Oct/0","https://seclists.org/bugtraq/2019/Oct/1","https://seclists.org/bugtraq/2019/Sep/25","https://security.gentoo.org/glsa/201911-04","https://security.netapp.com/advisory/ntap-20190919-0002/","https://support.f5.com/csp/article/K97324400?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4376-1/","https://usn.ubuntu.com/4376-2/","https://usn.ubuntu.com/4504-1/","https://www.debian.org/security/2019/dsa-4539","https://www.debian.org/security/2019/dsa-4540","https://www.openssl.org/news/secadv/20190910.txt","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.tenable.com/security/tns-2019-09"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1563","description":"In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.9+11-0ubuntu1~18.04.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14782","versionConstraint":"< 11.0.9+11-0ubuntu1~18.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2020-14782","fix":{"state":"fixed","versions":["11.0.9+11-0ubuntu1~18.04.1"],"available":[{"date":"2020-10-27","kind":"advisory","version":"11.0.9+11-0ubuntu1~18.04.1"}]},"cvss":[],"epss":[{"cve":"CVE-2020-14782","date":"2026-10-08","epss":0.02272,"percentile":0.8254}],"risk":1.1360000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-14782"},"relatedVulnerabilities":[{"id":"CVE-2020-14782","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14782","date":"2026-10-08","epss":0.02272,"percentile":0.8254}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html","https://lists.debian.org/debian-lts-announce/2020/10/msg00031.html","https://security.gentoo.org/glsa/202101-19","https://security.netapp.com/advisory/ntap-20201023-0004/","https://www.debian.org/security/2020/dsa-4779","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14782","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]},{"artifact":{"id":"e8067ad52b8b6a7c","cpes":["cpe:2.3:a:openjdk-11-jre-headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre-headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre_headless:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11-jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11_jre:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_11:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-11-jre-headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_11_jre_headless:11.0.7\\+10-2ubuntu2\\~18.04:*:*:*:*:*:*:*"],"name":"openjdk-11-jre-headless","purl":"pkg:deb/ubuntu/openjdk-11-jre-headless@11.0.7%2B10-2ubuntu2~18.04?arch=amd64&distro=ubuntu-18.04&upstream=openjdk-lts","type":"deb","version":"11.0.7+10-2ubuntu2~18.04","language":"","licenses":["sha256:d29997e11d07b36280d0c3a17c9603214ebf30174a2c04ea5db536cb69657258"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-11-jre-headless/copyright","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/usr/share/doc/openjdk-11-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","layerID":"sha256:950efb1a391b01f1267100c816dc76b233e4f37d0200d4a4a3b9da9198485af3","accessPath":"/var/lib/dpkg/info/openjdk-11-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjdk-lts"}]},"matchDetails":[{"fix":{"suggestedVersion":"11.0.17+8-1ubuntu2~18.04"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-21618","versionConstraint":"< 11.0.17+8-1ubuntu2~18.04 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"18.04"},"package":{"name":"openjdk-lts","version":"11.0.7+10-2ubuntu2~18.04"},"namespace":"ubuntu:distro:ubuntu:18.04"}}],"vulnerability":{"id":"CVE-2022-21618","fix":{"state":"fixed","versions":["11.0.17+8-1ubuntu2~18.04"],"available":[{"date":"2022-11-09","kind":"advisory","version":"11.0.17+8-1ubuntu2~18.04"}]},"cvss":[],"cwes":[{"cve":"CVE-2022-21618","cwe":"CWE-287","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21618","date":"2026-10-08","epss":0.02271,"percentile":0.82529}],"risk":1.1355,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:18.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-21618"},"relatedVulnerabilities":[{"id":"CVE-2022-21618","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-21618","cwe":"CWE-287","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-21618","date":"2026-10-08","epss":0.02271,"percentile":0.82529}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/37QDWJBGEPP65X43NXQTXQ7KASLUHON6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ARF4QF4N3X5GSFHXUBWARGLISGKJ33R/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QLQ7OD33W6LT3HWI7VYDFFJLV75Y73K/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXSBV3W6EP6B7XJ63Z2FPVBH6HAPGJ5T/","https://security.gentoo.org/glsa/202401-25","https://security.netapp.com/advisory/ntap-20221028-0012/","https://www.oracle.com/security-alerts/cpuoct2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-21618","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:34:13.992Z","grype_db_version":"2026-10-09T06:32:32.000Z"}